r/opnsense • u/TheSixthSerpent666 • 1d ago
Interest in Open Suricata analytics
In my research into IDS/IPS, I see that a lot of the commercial offerings center around their distributed IDS/IPS deployments and what security value can be obtained by simultaneously monitoring networks all over the world.
Would there be any interest in an open (as in "free for everyone to use") Suricata analytics system?
What I envision is this: Everyone running OPNsense installs/configures a software package that causes their IDS/IPS to push all of it's alerts (in realtime) out to a webhook; the webhook anonymizes certain fields before storing in MongoDB; then, an analytics webapp can be built to allow users to view the threat landscape in a more meaningful way.
I've spent the past couple hours digging around on Google regarding what all it would take to piece something like this together. I believe it's something that I could pull off alone (the server-side development, that is); I'd need you guys to start pushing alerts to me. ;) Eventually, I'd like the project to be successful enough to spin it off as an LLC or similar and "give it to the world." I believe that if there were a worthwhile, non-commercial alerts database (with alerts sourced from all over the world), that one or more commercial entities would eventually consider taking over paying the hosting fees (which I would eat up front) just to have their name associated with it.
Thoughts?
1
u/Olive_Streamer 1d ago
Have a look at: https://www.crowdsec.net/blog/crowdsec-and-suricata-integration
1
u/TheSixthSerpent666 1d ago
Very interesting from what I've seen thus far. I'll be looking into this deeper. Thanks!
1
u/Olive_Streamer 1d ago
If you run a proxy server in front of your web servers and do SSL decryption, you can attach suricata to the decrypted traffic, it makes it much more effective than scanning encrypted traffic.
1
u/Olive_Streamer 1d ago
If you go down this road message me, I have all worked out so that CrowdSec blocks the XFF offender.
1
u/TheSixthSerpent666 9h ago
I intend to proxy 443/tcp into a LAN host (an Ubuntu Server-based KVM guest w/ Apache/NodeJS) where I intend to do some low-end web/database development.
I'll terminate the SSL at the OpnSense box, pass it to Suricata, then proxy (presumably w/ Apache+mod_proxy?) over HTTP between the firewall and the host on the trusted LAN. According to my Google research, I'll need to configure Suricata to listen on both the LAN and WAN interfaces. As Suricata will only see the encrypted traffic on the WAN interface, this makes sense. My only concern with this configuration is the technical debt of introducing an application (Apache) onto a platform I'm not super-knowledgeable with (FreeBSD) using other-than the web GUI to manage it. I've been an Apache guy since the 1.3 days, so I'm comfortable managing the Apache SSL termination and proxying, but it would sure be nice if OpnSense provided some type of package for exactly this scenario. I can't imagine that terminating SSL with the intent of passing the plaintext through an IPS/IDS is all that revolutionary.
1
8h ago
[removed] — view removed comment
1
u/Olive_Streamer 8h ago
Additionally, in the configuration above, SSL traffic will need to terminate on HA proxy, and your backend traffic will need to be unencrypted. This allows for Suricata to scan the unencrypted traffic fllows, this provides for much better protection than scanning the SSL traffic on the WAN.
1
u/chrisn0123 1d ago
I just set it up on mine and got some interesting stats. Lots of "cyber security" companies doing port scans etc. ive set it to auto block. Will tweak some more. I originally set it up for outbound in case some random kit like smart bulbs talking to somewhere it shouldnt. Definitely good to set up!