| | 12 | * 實驗組 : Cloud compute |
| | 13 | |
| | 14 | 1. 修改 /etc/snort/snort.conf |
| | 15 | |
| | 16 | {{{ |
| | 17 | var HOME_NET any |
| | 18 | var EXTERNAL_NET !$HOME_NET |
| | 19 | |
| | 20 | }}} |
| | 21 | |
| | 22 | 2. 紀錄警訊 |
| | 23 | |
| | 24 | {{{ |
| | 25 | |
| | 26 | $ sudo snort -c /etc/snort/snort.conf -i eth0 |
| | 27 | |
| | 28 | $ sudo tcpreplay -i eth0 --topspeed sp1.tcpdump |
| | 29 | |
| | 30 | }}} |
| | 31 | |
| | 32 | 3. 分析格式 |
| | 33 | |
| | 34 | {{{ |
| | 35 | |
| | 36 | }}} |
| | 37 | |
| | 38 | 4. 紀錄雲端運算時間 |
| | 39 | |
| | 40 | * 對照組:mysql database |
| | 41 | 1. 修改 /etc/snort/snort.conf |
| | 42 | {{{ |
| | 43 | var HOME_NET any |
| | 44 | var EXTERNAL_NET !$HOME_NET |
| | 45 | output database: log, mysql, user=snort password=snort dbname=snort host=localhost |
| | 46 | }}} |
| | 47 | |
| | 48 | 2. 紀錄警訊 |
| | 49 | > 同前 |
| | 50 | |
| | 51 | 3. 紀錄mysql運算時間 |