Venus Fly Trap server, a network anomaly detection engine
952
A network anomaly detection engine
VFT straddles the line between a network intrusion detection system (NIDS), host-based intrustion detection system (HIDS), and a honeypot. It is simultaneously all and none of these. Designed to work best across a fleet of clients, VFT detects connections and potential scanning activity that may evade your NIDS or HIDS, but without requiring setup of heavier systems such ELK or relying on event correlation from Datadog (although that is totally an option).
vft-server --bind 0.0.0.0:9999 --cert some-cert.pem --key some-key.pem --secret sharedsecret
Or with Docker:
docker run -d -it --name vft -v $(pwd)/certs:/certs -p 9999:9999 vft vft-server --bind 0.0.0.0:9999 --ssl --cert /certs/some-cert.pem --key /certs/some-key.pem --secret sharedsecret
VFT is a pair of binaries that work as a client/agent and a server. The vft-agent can be found here
vft-server listens for incoming agent connections, correlates activity, and reports any potentially interesting anomalies. Events such as frequent hits to the same "trap" port across all agents, frequent hits from the same address across all agents, and frequent hits to the same agent are all examples of activity that will be alerted on.
The server binds to 0.0.0.0:9999 by default.
$ vft-server --secret somesecret --ssl --cert ./cert.pem --key ./key.pem --bind 0.0.0.0:9999
All flags are optional, but the server will fail out if --ssl is enabled and --cert and --key are not also provided.
Content type
Image
Digest
Size
11.7 MB
Last updated
almost 8 years ago
docker pull madurosecurity/vft-server