Quantcast
Channel: WebSyrup.net | Software Downloads » dependencies
Viewing all articles
Browse latest Browse all 175

Cyberprobe 0.20

$
0
0

Cyberprobe is a distributed architecture for real-time monitoring of networks against attack. The software consists of two components: cyberprobe, which collects data packets and forwards it over a network in standard streaming protocols; and cybermon, which receives the streamed packets, decodes the protocols, and interprets the information.
Cyberprobe can optionally be configured to receive alerts from Snort. In this configuration, when an alert is received, the IP source address associated with the alert is dynamically targeted for a period of time. Collecting data and forwarding over the network to a central collection point allows for a much more “industrialized” approach to intrusion detection.
The monitor, cybermon, is highly configurable using LUA, allowing you to do a great many things with captured data: summarize, hexdump, store, and respond with packet injections.

Release Notes: This release adds more protocol decode support, with the ability to decode HTTP and DNS protocols. An overhaul of the LUA configuration language allows you to harness the decoded protocol information and act on it. Also added are a couple of packet forgery techniques, with TCP reset and DNS packet forgery added. This allows you to detect attacks and respond with packet injection in order to disrupt the attack.
Finally, to coincide with 0.20, the Web site has been updated with a QuickStart tutorial to help get you working with cyberprobe and cybermon components.

Tags: IDS, Packet Capturing, Packet Analyzer

Licenses: GPLv3

Download Software page:
Cyberprobe 0.20


Viewing all articles
Browse latest Browse all 175

Trending Articles