InterSect [InterSect Swish]
Search Our Site
  Enter Search Terms
News
Snare for Windows - Snare for Windows Version 3.0.0 is now available. This new version fixes some bugs noticed on some Windows OS versions.
NISPOM and PCI An appendix to the Snare Server User's Guide now contains guidance on how to comply with NISPOM and PCI Data Security Standard
Snare Server Version 4.2.1 is now available. This new version includes a single CD installation for all packages and the OS.
Stats on the agent downloads and visits to our web server are avialble from Statistics.

National Industrial Security Operating Manual (NISPOM)

NISPOM provides uniform policy guidance and requirements associated with the restrictions, requirements and other safeguards that are necessary to control, and prevent unauthorised disclosure of classified information released by U.S. Government Executive Branch Departments and Agencies to their contractors.

The Snare Server, from InterSect Alliance, provides a centralised collection, analysis, reporting and archival function for a variety of audit log sources, and is used by several organisations to meet federal guidelines associated with NISPOM - particularly the requirements stated in Chapter 8.

On installation, the Snare Server runs a configuration wizard, which allows an administrator to install and configure objectives which are specifically targeted to address NISPOM Chapter 8 requirements.

Related Information

The following links provide more information on NISPOM Chapter 8.


Evaluated Configurations

Linux

The following configuration contributed to systems passing a PL-1 Multiuser Defence Security Service (DSS) evaluation on Red Hat Enterprise 4.0, in 2005. The Snare agent version was 0.9.8. Snare for Linux 1.0+ requires a slightly different ruleset due to changes in the underlying kernel.

Further details are available from the "Snare, Linux and NISPOM" thread discussed above.
Thanks to Cliff Partlow for the configuration.

[Remote]
allow=1
listen_port=6161

[Output]
file=/var/log/audit/audit.log

[Objectives]
criticality=4 event=Process_Events return=.* user=.* match=.*
criticality=4 event=open(.*),mkdir,mknod,link,symlink return=Success user!=root match=^/etc/shadow$
criticality=2 event=open(.*),mkdir,mknod,link,symlink return=Failure user!=root match=^/etc/shadow$
criticality=4 event=open(O_WRONLY|O_RDWR|O_CREAT|O_TRUNC|O_APPEND),mkdir,mknod,link,symlink return=Success user!=root match=^/etc/passwd$
criticality=2 event=open(O_WRONLY|O_RDWR|O_CREAT|O_TRUNC|O_APPEND),mkdir,mknod,link,symlink return=Failure user!=root match=^/etc/passwd$
criticality=2 event=open(.*),mkdir,mknod,link,symlink return=Failure user=.* match=^(/var/log|/etc)/audit.*
criticality=3 event=open(.*),mkdir,mknod,link,symlink return=Success user=.* match=^(/var/log|/etc)/audit.*
criticality=4 event=open(O_WRONLY|O_RDWR|O_CREAT|O_TRUNC|O_APPEND),mkdir,mknod,link,symlink return=Success user!=root match=^/(sbin|usr/sbin|bin|usr/bin|usr/X11R6/bin|usr/bin/X11)/.*
criticality=1 event=execve,exit return=Success user=.* match=^/bin/su$
criticality=2 event=execve,exit return=Failure user=.* match=^/bin/su$
criticality=3 event=open(O_TRUNC|O_APPEND),chmod,rename,truncate,chown,lchown return=Failure user!=root match=^/etc/.*
criticality=2 event=open(.*),mkdir,mknod,link,symlink,rename,unlink return=Failure user!=root match=^/var/log/.*
criticality=1 event=mount,umount return=Failure user!=root match=.*
criticality=0 event=chroot return=* user=.* match=.*
criticality=0 event=reboot return=* user=.* match=.*
criticality=1 event=accept return=* user!=root match=.*
criticality=1 event=mount,umount return=* user=.* match=.*
criticality=1 event=mkdir,mknod,link,symlink,rename,unlink return=Failure user=.* match=.*


##### DSS Known Requirerd Objectives for PL-1 #####

criticality=4 event=rmdir,unlink return=Failure user=.* match=^/(sbin|usr/sbin|bin|usr/bin|usr/X11R6/bin|usr/bin/X11|lib|usr/lib|etc|boot|var/log)/.*
criticality=4 event=open(.*),creat,mkdir,mknod,link,symlink,truncate,ftruncate return=Failure user=.* match=^/(sbin|usr/sbin|bin|usr/bin|usr/X11R6/bin|usr/bin/X11|lib|usr/lib|etc|boot|var/log)/.*
criticality=4 event=chmod,rename,chown return=Failure user=.* match=^/(sbin|usr/sbin|bin|usr/bin|usr/X11R6/bin|usr/bin/X11|lib|usr/lib|etc|boot|var/log)/.*
criticality=4 event=setuid,setreuid,setresuid,setgid,setregid,setresgid return=Failure user=.* match=.*
criticality=4 event=reboot,create_module,delete_module,chroot,mount,umount return=Failure user=.* match=.*


##### DSS Known Requirerd Objectives for PL-2 machines, you must have the above objectives listed in audit.conf, in addition to the following: #####

criticality=4 event=rmdir,unlink return=Failure,Success user=.* match=^/(home)/.*
criticality=4 event=open(.*),creat,mkdir,mknod,link,symlink,truncate,ftruncate return=Failure user=.* match=^/(home)/.*
criticality=4 event=chmod,rename,chown return=Failure user=.* match=^/(home)/.*




Snare provides a central collection, analysis, reporting and archival capability for a variety of operating systems, appliances, and servers, including:
Windows NT/2000/XP/2003
Linux
Solaris
AIX
Irix
Tru64
ACF2
RACF
CISCO Routers / IOS
CISCO 6500 Firewall
CISCO Pix Firewall
CyberGuard Firewall
CheckPoint Firewall 1
Gauntlet Firewall
Netgear Firewall
Netgear Router
Netscreen Firewall
Nortel VPN devices
IPTables Firewall
Microsoft ISA Server
Microsoft IIS Server
Microsoft FTP Server
Microsoft Exchange Server
Microsoft Chat Server
Microsoft Proxy Server
Apache
Squid
Point of Sale terminals (POS)
Lotus Notes
Snort NIDS
IBM Socks Server
Universal Log Format
Generic Syslog Data
  
Snare Server
The Snare Server builds on the success of our Open Source audit & event log agents. When used in combination, our Snare agents, and Server provide a robust and effective resource for event log management.

Snare Server Snort Report
This link will take you to a small report exported from our Snare Server, that shows attacks against our website
Copyright (c) 1999-2007 InterSect Alliance Pty Ltd