Sign inSign up

madurosecurity/vft-server

By madurosecurity

•Updated almost 8 years ago

Venus Fly Trap server, a network anomaly detection engine

Image
1

952

madurosecurity/vft-server repository overview

⁠Venus Fly Trap

A network anomaly detection engine

⁠Summary

GoDoc Reference

VFT straddles the line between a network intrusion detection system (NIDS), host-based intrustion detection system (HIDS), and a honeypot. It is simultaneously all and none of these. Designed to work best across a fleet of clients, VFT detects connections and potential scanning activity that may evade your NIDS or HIDS, but without requiring setup of heavier systems such ELK or relying on event correlation from Datadog (although that is totally an option).

⁠Quick start

⁠Server

vft-server --bind 0.0.0.0:9999 --cert some-cert.pem --key some-key.pem --secret sharedsecret

Or with Docker:

docker run -d -it --name vft -v $(pwd)/certs:/certs -p 9999:9999 vft vft-server --bind 0.0.0.0:9999 --ssl --cert /certs/some-cert.pem --key /certs/some-key.pem --secret sharedsecret

⁠How it works

VFT is a pair of binaries that work as a client/agent and a server. The vft-agent can be found here⁠

vft-server listens for incoming agent connections, correlates activity, and reports any potentially interesting anomalies. Events such as frequent hits to the same "trap" port across all agents, frequent hits from the same address across all agents, and frequent hits to the same agent are all examples of activity that will be alerted on.

The server binds to 0.0.0.0:9999 by default.

$ vft-server --secret somesecret --ssl --cert ./cert.pem --key ./key.pem --bind 0.0.0.0:9999

All flags are optional, but the server will fail out if --ssl is enabled and --cert and --key are not also provided.

Tag summary

Content type

Image

Digest

Size

11.7 MB

Last updated

almost 8 years ago

docker pull madurosecurity/vft-server