SolSoCoG
0
Heyho,
wollte mal fragen ob das üblich ist das snortd auf der main ip in/out jeweils ca. 50-100MBit/s konstant verursacht (cap ist 10000MBit/s)
Hier mal snort -v -i eth0 Ausgabe
wollte mal fragen ob das üblich ist das snortd auf der main ip in/out jeweils ca. 50-100MBit/s konstant verursacht (cap ist 10000MBit/s)
Hier mal snort -v -i eth0 Ausgabe
Code:
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.322613 A.A.A.A:48684 -> 224.1.1.75:1235
UDP TTL:1 TOS:0x0 ID:27930 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.322637 A.A.A.A:53392 -> 224.1.1.44:1235
UDP TTL:1 TOS:0x0 ID:18492 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.322813 A.A.A.A:45727 -> 224.1.1.71:1235
UDP TTL:1 TOS:0x0 ID:22314 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323005 A.A.A.A:46768 -> 224.1.1.30:1234
UDP TTL:1 TOS:0x0 ID:8603 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
(snort_decoder) WARNING: IP dgm len > captured len
04/28-22:51:43.323166 A.A.A.A:36380 -> 224.1.1.84:1235
UDP TTL:1 TOS:0x0 ID:48676 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323185 A.A.A.A:59241 -> 224.1.1.121:1235
UDP TTL:1 TOS:0x0 ID:55067 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323216 A.A.A.A:56081 -> 224.1.1.68:1235
UDP TTL:1 TOS:0x0 ID:18437 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323324 A.A.A.A:40493 -> 224.1.1.85:1235
UDP TTL:1 TOS:0x0 ID:31983 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323381 A.A.A.A:53124 -> 224.1.1.52:1235
UDP TTL:1 TOS:0x0 ID:38452 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323391 A.A.A.A:44539 -> 224.1.1.83:1235
UDP TTL:1 TOS:0x0 ID:5508 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323407 A.A.A.A:58325 -> 224.1.1.38:1234
UDP TTL:1 TOS:0x0 ID:16152 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323441 A.A.A.A:57340 -> 224.1.1.33:1234
UDP TTL:1 TOS:0x0 ID:63454 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323509 A.A.A.A:48575 -> 224.1.1.8:1234
UDP TTL:1 TOS:0x0 ID:33424 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323597 A.A.A.A:33399 -> 224.1.1.27:1234
UDP TTL:1 TOS:0x0 ID:17569 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323709 A.A.A.A:43710 -> 224.1.1.66:1235
UDP TTL:1 TOS:0x0 ID:50376 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323769 A.A.A.A:50776 -> 224.1.1.56:1235
UDP TTL:1 TOS:0x0 ID:25662 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323906 A.A.A.A:37793 -> 224.1.1.64:1235
UDP TTL:1 TOS:0x0 ID:45871 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.323918 A.A.A.A:36281 -> 224.1.1.82:1235
UDP TTL:1 TOS:0x0 ID:17754 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
(snort_decoder) WARNING: IP dgm len > captured len
04/28-22:51:43.324163 A.A.A.A:45331 -> 224.1.1.24:1234
UDP TTL:1 TOS:0x0 ID:36440 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.324312 A.A.A.A:41608 -> 224.1.1.19:1234
UDP TTL:1 TOS:0x0 ID:12315 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.324469 A.A.A.A:53528 -> 224.1.1.63:1235
UDP TTL:1 TOS:0x0 ID:27282 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
(snort_decoder) WARNING: IP dgm len > captured len
04/28-22:51:43.324584 A.A.A.A:51718 -> 224.1.1.87:1235
UDP TTL:1 TOS:0x0 ID:24569 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.324741 A.A.A.A:33860 -> 224.1.1.28:1234
UDP TTL:1 TOS:0x0 ID:61611 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
04/28-22:51:43.324995 A.A.A.A:39993 -> 224.1.1.47:1235^C
UDP TTL:1 TOS:0x0 ID:46514 IpLen:20 DgmLen:1344 DF
Len: 1316
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
===============================================================================
Run time for packet processing was 21.358046 seconds
Snort processed 60104 packets.
Snort ran for 0 days 0 hours 0 minutes 21 seconds
Pkts/sec: 2862
===============================================================================
Memory usage summary:
Total non-mmapped bytes (arena): 794624
Bytes in mapped regions (hblkhd): 12640256
Total allocated space (uordblks): 671168
Total free space (fordblks): 123456
Topmost releasable block (keepcost): 106640
===============================================================================
Packet I/O Totals:
Received: 326621
Analyzed: 60104 ( 18.402%)
Dropped: 265201 ( 44.811%)
Filtered: 0 ( 0.000%)
Outstanding: 266517 ( 81.598%)
Injected: 0
===============================================================================
Breakdown by protocol (includes rebuilt packets):
Eth: 60104 (100.000%)
VLAN: 0 ( 0.000%)
IP4: 60051 ( 99.912%)
Frag: 0 ( 0.000%)
ICMP: 18 ( 0.030%)
UDP: 39034 ( 64.944%)
TCP: 14875 ( 24.749%)
IP6: 27 ( 0.045%)
IP6 Ext: 27 ( 0.045%)
IP6 Opts: 0 ( 0.000%)
Frag6: 0 ( 0.000%)
ICMP6: 2 ( 0.003%)
UDP6: 22 ( 0.037%)
TCP6: 3 ( 0.005%)
Teredo: 0 ( 0.000%)
ICMP-IP: 0 ( 0.000%)
IP4/IP4: 0 ( 0.000%)
IP4/IP6: 0 ( 0.000%)
IP6/IP4: 0 ( 0.000%)
IP6/IP6: 0 ( 0.000%)
GRE: 0 ( 0.000%)
GRE Eth: 0 ( 0.000%)
GRE VLAN: 0 ( 0.000%)
GRE IP4: 0 ( 0.000%)
GRE IP6: 0 ( 0.000%)
GRE IP6 Ext: 0 ( 0.000%)
GRE PPTP: 0 ( 0.000%)
GRE ARP: 0 ( 0.000%)
GRE IPX: 0 ( 0.000%)
GRE Loop: 0 ( 0.000%)
MPLS: 0 ( 0.000%)
ARP: 26 ( 0.043%)
IPX: 0 ( 0.000%)
Eth Loop: 0 ( 0.000%)
Eth Disc: 0 ( 0.000%)
IP4 Disc: 6104 ( 10.156%)
IP6 Disc: 0 ( 0.000%)
TCP Disc: 0 ( 0.000%)
UDP Disc: 0 ( 0.000%)
ICMP Disc: 0 ( 0.000%)
All Discard: 6104 ( 10.156%)
Other: 20 ( 0.033%)
Bad Chk Sum: 6524 ( 10.855%)
Bad TTL: 0 ( 0.000%)
S5 G 1: 0 ( 0.000%)
S5 G 2: 0 ( 0.000%)
Total: 60104
===============================================================================
Snort exiting