软件包: hlbr (1.7.2-2 以及其他的)
IPS that runs over layer 2 (no TCP/IP stack required)
HLBR stands for Hogwash Light BR. It is a Brazilian fork of Jason Larsen's Hogwash Intrusion Prevention System (IPS). Its main feature is that it can run directly over OSI model layer 2, which means it doesn't even require a TCP/IP stack, running as a bridge.
HLBR comes with a set of rules to detect known malicious network traffic, and you can define your own rules as well. Packet handling include options like dropping or diverting it to another machine (such as a honeypot). Since it works like a bridge and doesn't requires an IP address, it is invisible to intruders. HLBR is a firewall component and must be put before a Intrusion Detection System (IDS). The IDS (Snort or other) will show all suspect traffic doesn't blocked and it can be used to compose new rules to IPS.
HLBR rule definition language has support for regular expressions (Perl). All blocked traffic is dumped in log under tcpdump format.
其他与 hlbr 有关的软件包
|
|
|
-
- dep: libc6 (>= 2.10) [hppa, sh4]
- Embedded GNU C Library: Shared libraries
同时作为一个虚包由这些包填实: libc6-udeb
- dep: libc6 (>= 2.11) [powerpcspe]
- dep: libc6 (>= 2.13) [s390x]
- dep: libc6 (>= 2.3) [amd64, sparc64]
- dep: libc6 (>= 2.3.6-6~) [i386]
- dep: libc6 (>= 2.4) [armel, armhf, mips, mipsel, powerpc, s390]
- dep: libc6 (>= 2.5) [avr32]
- dep: libc6 (>= 2.5-5) [m68k]
- dep: libc6 (>= 2.6) [sparc]
-
- dep: libc6.1 (>= 2.3) [ia64]
- Embedded GNU C Library: Shared libraries
同时作为一个虚包由这些包填实: libc6.1-udeb
- dep: libc6.1 (>= 2.4) [alpha]
-
- dep: libpcre3 (>= 7.7) [除 armhf, s390x]
- Perl 5 Compatible Regular Expression Library - runtime files
- dep: libpcre3 (>= 8.10) [armhf, s390x]
-
- rec: tcpdump
- command-line network traffic analyzer
-
- sug: hlbrw
- assistant to help make new rules to HLBR
下载 hlbr
| 硬件架构 | 版本 | 软件包大小 | 安装后大小 | 文件 |
|---|---|---|---|---|
| alpha | 1.7.2-2 | 101.8 kB | 440.0 kB | [文件列表] |
| amd64 | 1.7.2-2 | 90.1 kB | 392.0 kB | [文件列表] |
| armel | 1.7.2-2 | 84.3 kB | 372.0 kB | [文件列表] |
| armhf | 1.7.2-2 | 81.3 kB | 281.0 kB | [文件列表] |
| avr32 (非官方移植版) | 1.7.2-2 | 76.4 kB | 344.0 kB | [文件列表] |
| hppa | 1.7.2-2 | 90.2 kB | 388.0 kB | [文件列表] |
| i386 | 1.7.2-2 | 80.6 kB | 368.0 kB | [文件列表] |
| ia64 | 1.7.2-2 | 120.1 kB | 944.0 kB | [文件列表] |
| m68k (非官方移植版) | 1.6-2 | 69.9 kB | 356.0 kB | [文件列表] |
| mips | 1.7.2-2 | 84.9 kB | 416.0 kB | [文件列表] |
| mipsel | 1.7.2-2 | 84.5 kB | 416.0 kB | [文件列表] |
| powerpc | 1.7.2-2 | 88.8 kB | 400.0 kB | [文件列表] |
| powerpcspe (非官方移植版) | 1.7.2-2+b100 | 87.2 kB | 388.0 kB | [文件列表] |
| s390 | 1.7.2-2 | 89.8 kB | 388.0 kB | [文件列表] |
| s390x | 1.7.2-2 | 99.3 kB | 387.0 kB | [文件列表] |
| sh4 (非官方移植版) | 1.7.2-2 | 82.3 kB | 380.0 kB | [文件列表] |
| sparc | 1.7.2-2 | 83.8 kB | 380.0 kB | [文件列表] |
| sparc64 (非官方移植版) | 1.7.2-2 | 86.9 kB | 392.0 kB | [文件列表] |
