Know your assets with PRADS

Author

Kacper Wysocki

Contact

kwy@redpill-linpro.com

Date

March 23, 2011

Intro to PRADS

Overview

Why PRADS

How we do it

Getting it

http://github.com/gamelinux/prads/downloads

Getting geeky

Design

+-------+
|       |<-----{config
| prads |<-----{arguments
|       |<-----{signatures
+-------+
    | (init, drop privs, chroot, daemonize..)
    V
+---------
| packet |--> (source:port destination:port)-->[connection]-->{output
+---------                                         ^
    |                                              |
    v                                              |
 +-------+                                         v
 |dissect|<--> (vlan eth arp ip tcp udp) ---> [packet info]
 +-------+                                        /
    |       _____________________________________/
    v      /                                       ______________
+-------- /                                       /__standard out
| asset |/                                       /__file
+-------+----------------------->{output plugins/_fifo
   |     \                                      \__graphviz(?)
   v      \                                      \__your plugin here
 +--+      +----------+                           \_______________-k
 |os|      | services |
 +--+      ------------

Using the data

The future

Getting it

http://github.com/gamelinux/prads/downloads

Installation, deb

apt-get install libpcre3 libpcap
dpkg -i prads_0.2.3-1_amd64.deb

Repository? Working on it!

Setting it up

Using it

me@mine:~$ prads -h

Questions?

=> http://github.com/gamelinux/prads

kacper.blog.linpro.no

u.rdir.it

kwy@redpill-linpro.com

6BD0 3F9C 5F77 AD24 F60A
86EC FD82 7E34 674A 506F

Thanks!