Non-intrusive access monitoring scenario using attribute based signatures.
- Python 3.6 (verified to work) or possibly newer (untested) with the included base libraries
- Libraries charm-crypto, netfilterqueue and scapy and their respective requirements
- Configure addons by editing ABSSetup.py (JSON support may come later)
- Run
$ sudo iptables -A OUTPUT -p tcp -j NFQUEUEto send packets to the NFQUEUE handler. - Start the server process via
$ sudo python3.6 ABSSentinel.pywhich gives you the port number (host is the IP of the machine running it). - Start the client process as
$ sudo python3.6 ABSClient.py serverhost serverport networkaliaswhere:
serverhostandserverportare self-explanatory.networkaliasis the IP address representing the client in the packets sent to/from the client. This is for enabling NAT support.
- When finished, stop the processes via Ctrl-C and run
$ sudo iptables -D OUTPUT -p tcp -j NFQUEUEto stop the packet handler