Security Onion
Security Onion is a Linux-based distribution that is specifically designed to help you monitor your network and analyze any malicious activity. It helps to identify any intrusion, logs all the activities in your network, and provides valuable feedback.
The basic architecture of Security Onion is based on the server-client model. The agents are deployed on the client machines, they are also called Sensors. The job of the sensor is to sniff through the activities on the network on configured hosts and report it back to the Security Onion server. It provides an interface for an analyst to connect to its server from a client machine and execute queries and jobs for forensic purposes.
Note
A Linux distribution means that it is an operating system specifically configured with different tools to focus on a desired task.
Deployment scenarios
The Security onion model-based design allows you to configure it in three different ways:
- Standalone model
- Server-Sensor model
- Hybrid model
We will now...