Setting up NIDS



I am in the process of setting up a NIDS, consisting of Snort sensors, Barnyard MySQL and BASE, probably on OpenBSD. I have installed/compiled all modules on one computer, to confirm that they will work together (with snortsam and using OpenBSD "pf").

I have some notion, but still am a bit unsure where to install the different modules for sufficient performance for a live network. Searched the web but could not find any guides. I put Snort on the sensors and MySQL on a central server, but where do I put Barnyard and BASE for adequate performance? (On each sensor, the database server or a separate "transport"/webserver computer?)

I could test it myself, but I guess people have done it before and have some experience to share. I have a number of different computers, with varying specs and room for 3-4 NICs. What I'm looking for is a general guide with some info on what load Barnyard and BASE generate on CPU, and the data stream load (log file reading vs. database update).
.



Relevant Pages

  • Re: Where to place smokes/heat?
    ... how hard is it really to do a "clean" install of 3 ... closer to the ADT price point but i think it won't happen because ADT ... more window and door sensors (to protect my daughters upstairs room ... will be overseeing the install and the sales folks, ...
    (alt.security.alarms)
  • Re: Doubled up connections to security sensors? was Re: Z-WAVE question
    ... You would either have to install another switch adjacent to the first ... using Napco relays to follow the sensors but this was also too slow. ... now I plan to use a different faster controller to create the lighting path ...
    (comp.home.automation)
  • RE: lm_sensors on RHEL 3.0
    ... Dell systems have hidden the sensors chip such that I've never been able to ... Okay, so I find the lm_sensors docs, and they say to install i2c (which is ... I'm rapidly running into a brick wall. ... unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe ...
    (RedHat)
  • GSoC2007: cnst-sensors.2007-09-13.patch
    ... On this 256th day of 2007, it is my great pleasure to announce the completion of my GSoC2007 project on porting the sysctl hardware sensors framework from OpenBSD to FreeBSD. ... sysctldocumentation for hardware sensors ...
    (freebsd-hackers)
  • Re: another newbie, what to do with this Brinks alarm system?
    ... Brinks only uses EOL's for fire and heat sensors. ... else you can install your self. ...
    (alt.security.alarms)