Base

Perform analysis of intrusions that snort has detected on your network
Download

Base Ranking & Summary

Advertisement

  • Rating:
  • License:
  • GPL
  • Price:
  • FREE
  • Publisher Name:
  • Kevin Johnson
  • Publisher web site:
  • http://base.secureideas.net/
  • Operating Systems:
  • Mac OS X
  • File Size:
  • 932 KB

Base Tags


Base Description

Perform analysis of intrusions that snort has detected on your network BASE (Basic Analysis and Security Engine) is based on the code from the Analysis Console for Intrusion Databases (ACID) project and provides a web front-end to query and analyze the alerts coming from a SNORT IDS system.BASE is a web interface to perform analysis of intrusions that snort has detected on your network. It uses a user authentication and role-base system, so that you as the security admin can decide what and how much information each user can see. BASE also has a simple to use, web-based setup program for people not comfortable with editing files directly. What's New in This Release: · Fixed moving alerts with empty sig_priority -- Kevin Johnson for Michel Lundell · Added support for new chart type "unique alerts vs. number of alerts". Feature request no. 1659968 -- Juergen Leising · Further fixes in the setup procedure -- Juergen Leising · Disabled the pcap download possibility for sfportscan alerts, as these are just pseudo packets rather than real packets from the network. Answer to bug no. 1885673 -- Juergen Leising · Workaround and fixes for the bugs reported under no. 1699443 · Same or at least similar problem as under no. 1699443 sub 1. seems to be the one reported in Workaround. -- Juergen Leising · Workaround for bug no. 1762491. Related to the last two points (if not identical) -- Juergen Leising · Fix for bug no. 1974990 -- Juergen Leising · Added information to the docs about how to fix a pear::image::graph library bug preventing legends from being displayed with pie charts -- Juergen Leising · Added information to the docs about how to fix a missing fonts problem -- Juergen Leising · Fixes in PrintPortscanEvents(). Reaction to -- Juergen Leising · Workaround for a potential bug in preg_replace(); should solve problem mentioned in -- Juergen Leising · Some changes to the translations in languages/german.lang.php -- Juergen Leising · Added patch from Chris Ryan for german.lang.php -- Juergen Leising · Increased memory limit from 50 to 128 MB in base_graph_common.php as proposed by Chris Ryan on -- Juergen Leising · Added completely rewritten base.spec for building rpm packages of BASE. -- Juergen Leising · Workaround in base_graph_common.php for the case that signature classification names are missing. Even in this case different bars should be displayed, not just one "unclassified" one. -- Juergen Leising · Fixed small HTML bugs in the query form. -- Juergen Leising · Fixed syntax error in setup1.php in case of a wrong adodb path -- Juergen Leising · All of the sensors are now displayed in the search form. Same problem as in UpdateAlertCache() in base-php4/includes/base_cache.inc.php. -- Juergen Leising · Fixed SQL error with sig_priority when queried coming from the query form. -- Juergen Leising · Fixed "Select Signature from List" in the query form -- Juergen Leising · Added a README about the usage of Jason Brvenik's SnortUnified plugin. -- Juergen Leising · Fixed some smaller issues with Jason Brvenik's SnortUnified plugin and adjusted the whole plugin to perl-5.10 and Net::Packet-3.25, as shipped with fedora 9. -- Juergen Leising perl-5.10, as shipped with fedora 9. -- Juergen Leising · Fix for bug no. 2001211. -- Juergen Leising · Updated base.spec. The base-contrib rpm should now be installable under fedora 9. · uf_csv.pl puts out IP addresses in human readable form, now. -- Juergen Leising · Newly generated coordinates file world_map6.txt. -- Juergen Leising · Any potential relative paths of the adodb library are now converted to an absolute path -- Juergen Leising · Signatures from http://www.emergingthreats.net/ point now to http://docs.emergingthreats.net/SID -- Juergen Leising


Base Related Software