Security Onion 16.04.5.4 releases: Linux distro for intrusion detection, enterprise security monitoring, and log management
Security Onion is a free and open source Linux distribution for intrusion detection, enterprise security monitoring, and log management. It includes Elasticsearch, Logstash, Kibana, Snort, Suricata, Bro, OSSEC, Sguil, Squert, NetworkMiner, and many other security tools. The easy-to-use Setup wizard allows you to build an army of distributed sensors for your enterprise in minutes!
Below are several diagrams to represent the current architecture and deployment scenarios for Security Onion on the Elastic Stack.
High-Level Architecture Diagram
Curator – Manage indices through scheduled maintenance.
ElastAlert – Query Elasticsearch and alert on user-defined anomalous behaviour or other interesting bits of information.
FreqServer -Detect DGAs and find random file names, script names, process names, service names, workstation names, TLS certificate subjects and issuer subjects, etc.
DomainStats – Get additional info about a domain by providing additional context, such as creation time, age, reputation, etc.
- As always, make sure you verify the downloaded ISO image:
- When the ISO boots, choose the default option.
- Once the live desktop appears, double-click the “Install SecurityOnion” icon.
- On the “Installation type” screen, you may want to select the “Use LVM” option, as this will automatically create a /boot partition at the beginning of the drive and will give you more flexibility later. Check to see if the installer allocates a large amount of space to /home. If this is the case, you may want to shrink /home to give more space to /.
- If prompted with an encrypt home folder or encrypt partition option, DO NOT enable this feature.
- If asked about automatic updates, DO NOT enable automatic updates.
- The Keyboard Layout screen may be larger than your screen resolution and so the Continue button may be off the screen to the right like this:
You can simply slide the window over until you see the Continue button. For more information, please see:
- Once the installer completes, it should prompt to remove installation media and press ENTER. If instead it appears to hang, simply press the ENTER key to reboot. If that doesn’t work, you may forcibly restart the machine.