Security Onion – A Linux distro for intrusion detection
security-onion-solutions.github.io
security-onion-solutions.github.io
Notably, Security Onion and other tools are very difficult to use in cloud environments where you don't control the network! There are ways of getting a sensor access to the relevant traffic, but they require careful architecture. Even when set up properly, encrypted traffic defeats much of the deep packet inspection-based monitoring.
I think AWS's VPC Flow Logs are the foundation for better tools (disclaimer, my company develops these tools - [2]). I hope Azure and others follow suit.
[1] https://www.sans.org/reading-room/whitepapers/cloud/security...
[2] https://observable.net/blog/vpc-flow-logs-virtual-private-cl...
It will still take a lot of personnel time, though. Tuning alerts is critical.
NetFlow or VPC Flow Logs (in AWS) would work just as well for this also.
I would like to know if someone here has used both RSA Security Analytics and Security Onion, and what they think about how they compare against one another. The last time (which was about 2 years ago) RSA Sales people came to our site and showed the capabilities of their product, it seemed to exceed the capabilities of Security Onion, but I am still a junior guy in SecOps and I still have a lot to catch up and learn, so I don't have the sufficient knowledge and expertise to determine how they compare against one another and what the pros and cons of each product are.
Id imagine management / sales is probably "it's a black box and does good stuff", but curious about what level of detail is shared with the customer.
I am sure other people with Cisco Sourcefire and competitors will agree here.
If you want something better, hands-off doesn't work that well, you have to tune it to your network, because otherwise you'll drown in alerts for mundane things or leave a lot of potential on the table. (E.g. in an insurance office remote management connections or IRC are probably are worth an alert. In a dev shop these might happen all the time. Or not, depending on setup and policies)
Do I use it as an OS to monitor my infrastructure?
Eg. I use this OS to monitor and analyze my servers, containers, etc (which are running their own host/container OSes)
OR
Do I use this as an OS for my servers and my containers?
Eg. Security-Onion as the Host and Security-Onion containers on my infrastructure
It isn't quite clear from what I read/see on the landing-page.
Some of these interesting products then also put "intrusion prevention" into their product descriptions.
Isn't that too a questionable promise?
I have been using Alien Vault OSSIM (https://www.alienvault.com) for a few years and haven't seen any reason to switch. But this does look like a great project still.