Path to this page:
./
security/base,
Analysis engine to process a database of security events
Branch: pkgsrc-2011Q2,
Version: 1.4.3.1nb1,
Package name: base-1.4.3.1nb1,
Maintainer: pkgsrc-usersThe Basic Analysis and Security Engine (BASE) is a PHP-based analysis
engine to search and process a database of security events generated by
various IDSes, firewalls, and network monitoring tools. The features currently
include:
o Query-builder and search interface for finding alerts matching
on alert meta information (e.g. signature, detection time) as well as
the underlying network evidence (e.g. source/destination address, ports,
payload, or flags).
o Packet viewer (decoder) will graphically display the layer-3 and
layer-4 packet information of logged alerts
o Alert management by providing constructs to logically group alerts
to create incidents (alert groups), deleting the handled alerts or
false positives, exporting to email for collaboration, or archiving of
alerts to transfer them between alert databases.
o Chart and statistic generation based on time, sensor, signature, protocol,
IP address, TCP/UDP ports, or classification
Required to run:[
mail/pear-Mail] [
mail/pear-Mail_Mime] [
net/php-sockets] [
graphics/pear-Image_Color] [
graphics/pear-Image_Graph] [
graphics/php-gd] [
lang/perl5] [
math/pear-Numbers_Roman] [
math/pear-Numbers_Words]
Package options: mysql
Master sites:
SHA1: bf0a9bbc7131eb84d4b85d25e2fe878da31582c4
RMD160: e12ec80997df17f4bf3e8ea016da6fc0414044c1
Filesize: 946.065 KB
Version history: (Expand)
- (2011-08-05) Package added to pkgsrc.se, version base-1.4.3.1nb1 (created)