Cyber Protection and Hardening
, Security Onion
Introduction
Setup
Cyber Protection and Hardening Course
,Introducton - Background
• Security Onion is a turn-key Network Security Monitoring
(NSM) solution/distribution, intended for rapid deployment of
server, sensor, and analyst components to monitor your
network.
• It was created by Doug Berks when he realized there was a
deficiency in the antequated model utilized to assemble a fully
functional NSM system, whereby it took many months to build
and optimize a system, at which point the components of the
system had already become outdated, thereby requiring the
entire build cycle to again commence.
• Security Onion incorporates a exceptionally streamlined
process for basic configuring of an NSM system, utilizing an
intuitive point-and-click GUI setup interface.
Cyber Protection and Hardening Course
, Introducton - Background Cont.
• Security Onion has historically tracked one Long Term Support (LTS)
release behind the current Ubuntu LTS release. For instance, when
the current Ubuntu LTS release is 16.04 (April 2016,) then the
release the current version of Security Onion is utilizing would be
14.04 (April 2014.) This ensures exceptional testing has made stable
the distribution upon which Security Onion is built.
• As Security Onion is based upon the Ubuntu release Burks had
created a Launchpad Personal Package Archive (PPA) that hosts
all the packages utilized within Security Onion. This makes trivial the
process of converting an off-the-shelf Ubuntu Server installation into
a full-fleged Security Onion system with only a few keystores. This
also ensures rapid deployment of updates to components and
fixes, as they do not have to pass through the traditional process of
package releases to the Ubuntu apt repository.
Cyber Protection and Hardening Course
, Security Onion
Introduction
Setup
Cyber Protection and Hardening Course
,Introducton - Background
• Security Onion is a turn-key Network Security Monitoring
(NSM) solution/distribution, intended for rapid deployment of
server, sensor, and analyst components to monitor your
network.
• It was created by Doug Berks when he realized there was a
deficiency in the antequated model utilized to assemble a fully
functional NSM system, whereby it took many months to build
and optimize a system, at which point the components of the
system had already become outdated, thereby requiring the
entire build cycle to again commence.
• Security Onion incorporates a exceptionally streamlined
process for basic configuring of an NSM system, utilizing an
intuitive point-and-click GUI setup interface.
Cyber Protection and Hardening Course
, Introducton - Background Cont.
• Security Onion has historically tracked one Long Term Support (LTS)
release behind the current Ubuntu LTS release. For instance, when
the current Ubuntu LTS release is 16.04 (April 2016,) then the
release the current version of Security Onion is utilizing would be
14.04 (April 2014.) This ensures exceptional testing has made stable
the distribution upon which Security Onion is built.
• As Security Onion is based upon the Ubuntu release Burks had
created a Launchpad Personal Package Archive (PPA) that hosts
all the packages utilized within Security Onion. This makes trivial the
process of converting an off-the-shelf Ubuntu Server installation into
a full-fleged Security Onion system with only a few keystores. This
also ensures rapid deployment of updates to components and
fixes, as they do not have to pass through the traditional process of
package releases to the Ubuntu apt repository.
Cyber Protection and Hardening Course