Skip to content

Snort3 on Alpine Linux

Notifications You must be signed in to change notification settings

wtfbbqhax/Krakatoa

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

41 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Krakatoa

Docker-Image CI

Krakatoa-Image Logo

FROM Alpine Linux 3.20.2

This repository serves as a reference for building a custom Alpine container images based on the Alpine Linux. We make use of the Alpine Packaging tools abuild and apk to build a package repository local to the image itself. The local package repo builds package and subpackage targets from the software listed below.

Packaged Software

Several dependencies to build a complete version of Snort 3 are not part officially supported by Alpine Linux or what does exist did not meet my expectations so they've been pulled directly. Additionally, the Snort3, Snort3 Extra and LibDAQ packages were solely produced for Krakatoa.

How to

  1. Build Krakatoa image along with all packages

     make [build]
    
  2. Run Krakatoa

    # From your host system, create a new Krakatoa container.
    docker run --rm -ti krakatoa
        
    # Now you are in the Krakatoa runtime, we will now install 
    # packages from the @local repository.
    
    # 1st Install Snort3
    sudo apk add snort3@local
        
    # 2nd Install DAQ modules
    # You wont be able to do much until you install some DAQ
    # modules; by default Snort3 will use pcap daq.
    sudo apk add libdaq-pcap-module@local
    
    # However I prefer to use the afpacket module.
    sudo apk add libdaq-afpacket-module@local
    
    # You can install any of the packaged modules using `apk`. 
    # All modules that can be built for Linux are available.
    # sudo apk add libdaq-fst-module@local libdaq-dump-module@local
    
    # 3rd, Test your new Snort installation
    sudo snort --daq-dir /usr/local/lib/daq \
        -c /usr/local/etc/snort/snort.lua \
        -k none \
        --daq afpacket -i eth0 
  3. Persistent environment

    # Launch a new Krakatoa container in the background
    make start
    
    # Attach to running Krakatoa container
    make attach
    
    # Terminate the container
    make stop

Credits

Footnotes

  1. AbcIP version 2.4.1 is not a real tagged build, our package builds the HEAD of master. -wtfbbqhax