Showing posts with label System Monitoring. Show all posts
Showing posts with label System Monitoring. Show all posts

Monday, September 19, 2016

fail2ban: Protecting Servers

Generally recommending security measures is considered as the work of Application and Network Security team. But with introduction of DevOps and change in culture, everyone can contribute to it.

I usually recommend teams to embed these security tools into the development practices to ensure better end results. Coz if used properly tools like these help in maintaining better code quality and keeping infrastructure protected.

Few Open Source tools:
YASCA: http://www.scovetta.com/yasca.html
PMD: https://pmd.github.io/
SNORT: https://www.snort.org/
Fail2Ban: http://www.fail2ban.org/wiki/index.php/Main_Page

Let me explain more with an example:
With expanding infrastructure, we need tools to keep any on malicious attempts and take appropriate actions against them.
I use Fail2ban for this, which is one of the best Open Source tool available for this purpose.
How it works? Fail2ban can monitor logs/files based on defined patterns and take action when match exceeds the threshold.
Example: Pattern defined: <HOST> - - .*/create-account.html .*
Threshold Definition:
  • Take action if finds 20 connections within 20 seconds from one IP.
  • Blocks it for 1800 seconds. - Can be set to any other number or forever.
Actions: Actions like blocking IP via iptables, denying host via hosts.deny file, sending email notification, etc can be triggered once IPs/Users are caught for malicious activities.
Conclusion
Reach out to people who know about security tools and can help you setup these. Leave the rest to the tools to do their duty, small effort from every team member will help in making internet world more secure.

Important links:
Fail2ban Installation instructions: http://www.fail2ban.org/wiki/index.php/MANUAL_0_8
More Security Tools: https://www.owasp.org/index.php/Tools

Sample Configurations:
jail.conf:
[apache-custom-rule]
enabled  = true
action   = iptables-multiport[name=qa, port="http,https"]
filter   = apache-custom-rule
logpath  = /var/log/apache/access.log
maxretry = 20
findtime = 20
iptables-multiport.conf:
actionban = iptables -t nat -A PREROUTING -p tcp -s <ip> --dport 80 -j DNAT --to <Your Private IP>:80
                iptables -t nat -A PREROUTING -p tcp -s <ip> --dport 443 -j DNAT --to <Your Private IP>:443
actionunban = iptables -t nat -D PREROUTING -p tcp -s <ip> --dport 80 -j DNAT --to <Your Private IP>:80
                iptables -t nat -D PREROUTING -p tcp -s <ip> --dport 443 -j DNAT --to <Your Private IP>:443
apache-custom-rule:
failregex = <HOST> - - .*/accounts/u .*
                  <HOST> - - .* 403 .*

Wednesday, March 16, 2011

Nagios: Monitoring Systems & Applications

"Someone please help me."
These are the first words we usually say when we see our production system stuck/crashed due to some reasons.
But "Someone helps those who help themselves."  --Harpreet Singh ;-)

Now jokes apart.
But suppose we get an alert before the systems fails may be during the first stroke or when the load starting going high or may be when total processes were more or any thing related to our applications running on the server.

Wouldn't this be like a boon, a chance to save the system in time?
If you have seen my earlier posts you will find monit/munin doing the same, but as on the way of my learning, I found that nagios is a better (easy and more flexible/plugable) tool.
Before starting to explain on why my opinion changed I will ask you one question here.
What do you expect/need from any system/application monitoring tool?

The general answers would be:
 - Stable.
 - Good UI.
 - Easy Installation.
 - Easy configuration.
 - Good coverage over different applications and system.
 - etc. etc.

Now lets see if nagios answers all of these?

Like other tools nagios also has client-server architecture, which gives us freedom to monitor any number of  systems/applications from one nagios server.
It has a easy to understand & configure UI, through which you can do many things like scheduling, controlling alerts etc. And if you are a CLI lover (as most of Linux geeks are) then you can do all those from command line also.

Now here comes the most impressive part.
Nagios is highly flexible. First of all it has huge plugin base already available for you to work with.
But if that is not enough for you, then ask yourself just one questions.
Do I know how to write a script (bash, python etc)?

I usually say one line for nagios, that "If you can do it through CLI, you definitely can do it with nagios." Same is the answer for the question you asked yourself (above). If you can write a script to perform any action (login check, api calls, application query etc.) and get a small readable/understandable output (for both
success and failure cases). Then it's like a kids play to integrate it to nagios and see the same results in UI.

In simple words:
 - Write a script to perform certain action.
 - Copy that to the nagios script directory (just to ensure that you/anyone doesn't accidentally deletes it).
 - Add that to the nagios commands.
 - Call that command for the host you want.
 - And done.

Another plus part is that you can flaunt in front of your seniors about the work done (with minimal effort involved) ;-)