<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7652481.post3207576328334394365..comments</id><updated>2008-11-23T05:19:24.605-05:00</updated><category term='MySQL'/><category term='Tor'/><category term='NSM'/><category term='dns'/><category term='Snort'/><category term='book review'/><category term='Sguil'/><category term='apt'/><category term='hacking'/><category term='Perl'/><category term='Events'/><category term='WTF?'/><category term='OSSEC'/><category term='management'/><title type='text'>Comments on Infosec Potpourri: Alternative PCAP subsystems for Sguil</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.vorant.com/feeds/3207576328334394365/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3207576328334394365/comments/default'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2008/05/alternative-pcap-subsystems-for-sguil.html'/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7652481.post-4894563640437457992</id><published>2008-11-23T05:19:00.000-05:00</published><updated>2008-11-23T05:19:00.000-05:00</updated><title type='text'>H,&lt;br&gt;&lt;br&gt;Is SGUIL capable to handle huge mount of...</title><content type='html'>H,&lt;BR/&gt;&lt;BR/&gt;Is SGUIL capable to handle huge mount of raw data capture   in ISP with say 300Mbytes of data minimum ?&lt;BR/&gt;&lt;BR/&gt;In this case we need to equip with a huge harddisk for data capture in one week and does it make sense in practice ?&lt;BR/&gt;&lt;BR/&gt;Or SGUIL will only store raw data traces for those IDS alerts being fired? Thanks</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3207576328334394365/comments/default/4894563640437457992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3207576328334394365/comments/default/4894563640437457992'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2008/05/alternative-pcap-subsystems-for-sguil.html?showComment=1227435540000#c4894563640437457992' title=''/><author><name>Victor</name><uri>http://www.blogger.com/profile/17528849061159411850</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2008/05/alternative-pcap-subsystems-for-sguil.html' ref='tag:blogger.com,1999:blog-7652481.post-3207576328334394365' source='http://www.blogger.com/feeds/7652481/posts/default/3207576328334394365' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1358302484'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-5166845944447922863</id><published>2008-05-18T12:12:00.000-04:00</published><updated>2008-05-18T12:12:00.000-04:00</updated><title type='text'>Martin, thanks for the informative comment.  I fou...</title><content type='html'>Martin, thanks for the informative comment.  I found a similar speed increase, although I also found a performance bottleneck with the speed of the disk reads for the index files.  To get the best performance, it looks like the index files should probably be on a different disk than the pcaps, especially for more active networks such as yours.  I don't think SANCP provides a convenient way to do this yet, but perhaps I've simply overlooked it.  &lt;BR/&gt;&lt;BR/&gt;As for your point about typical searches and the retrieval time, you're right for UDP and TCP searches.  They're usually unique enough to give good performance, because at least one of the port numbers is bound to be ephemeral, and therefore acts like a database key.  For things like ICMP, which doesn't use ports, you could be getting more data than you wanted, though hopefully the sheer volume of ICMP between any two hosts isn't going to be very high.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3207576328334394365/comments/default/5166845944447922863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3207576328334394365/comments/default/5166845944447922863'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2008/05/alternative-pcap-subsystems-for-sguil.html?showComment=1211127120000#c5166845944447922863' title=''/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2008/05/alternative-pcap-subsystems-for-sguil.html' ref='tag:blogger.com,1999:blog-7652481.post-3207576328334394365' source='http://www.blogger.com/feeds/7652481/posts/default/3207576328334394365' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2136160136'/></entry><entry><id>tag:blogger.com,1999:blog-7652481.post-2212620472717196544</id><published>2008-05-17T12:49:00.000-04:00</published><updated>2008-05-17T12:49:00.000-04:00</updated><title type='text'>That's great to hear that you've updated SGUIL to ...</title><content type='html'>That's great to hear that you've updated SGUIL to use the pcap indexing.  For those of us who deal with big pipes, SGUIL really doesn't scale without some help.  I first suggested the indexing idea to John over a year ago, and he took it and ran with it, and now it's pretty solid.  &lt;BR/&gt;&lt;BR/&gt;I got similar disk cost results as you did.  Obviously, the smaller the average packet is, the larger the index will be with respect to the pcap.  Search performances were &lt;B&gt;several orders of magnitude&lt;/B&gt; faster.  My pcaps are somewhere in the neighborhood of 30 GB for a 15 minute time period, and indexing was able to retrieve arbitrary packets in about &lt;I&gt;5 seconds&lt;/I&gt;.  &lt;BR/&gt;&lt;BR/&gt;However, the indexing speed increase is only really apparent if the needle in the haystack you're looking for is fairly unique.  That is, if you're searching on some characteristic that exists many times throughout the index, (e.g. searching traffic for a very busy host) then you will see less of a speed increase because the bottleneck is not search but retrieval.  That said, typical searches are usually unique enough to see get the big performance boost.&lt;BR/&gt;&lt;BR/&gt;Many thanks to John for another great feature in SANCP and thanks to you for getting it into the hands of the larger community via SGUIL.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3207576328334394365/comments/default/2212620472717196544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/3207576328334394365/comments/default/2212620472717196544'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2008/05/alternative-pcap-subsystems-for-sguil.html?showComment=1211042940000#c2212620472717196544' title=''/><author><name>Martin</name><uri>http://www.blogger.com/profile/03975313410819886706</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2008/05/alternative-pcap-subsystems-for-sguil.html' ref='tag:blogger.com,1999:blog-7652481.post-3207576328334394365' source='http://www.blogger.com/feeds/7652481/posts/default/3207576328334394365' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-84778432'/></entry></feed>
