收集 Aruba IPS 日志

解析器版本: 3.0

支持的环境:

本文档介绍了如何使用 Bindplane 代理将 Aruba IPS 日志注入到 Google Security Operations。解析器会从 JSON 格式的日志中提取事件、通知、恶意 AP 和 WIDS AP 信息。它通过映射字段、处理各种事件类型(用户登录/退出、网络事件、安全事件)将原始日志数据转换为 UDM,并使用渠道、SSID、BSSID 和严重程度等上下文信息丰富数据。解析器还会执行时间戳规范化和畸形 JSON 错误处理。

准备工作

请确保满足以下前提条件:

  • Google SecOps 实例
  • 搭载 systemd 的 Windows 2016 或更高版本或 Linux 主机
  • 如果通过代理运行,请确保防火墙端口根据 Bindplane 代理要求处于开放状态
  • 对 Aruba 设备管理控制台或 CLI 的特权访问权限

获取 Google SecOps 提取身份验证文件

  1. 登录 Google SecOps 控制台。
  2. 依次前往 SIEM 设置 > 收集代理
  3. 下载数据注入身份验证文件
  4. 将文件安全地保存在将安装 Bindplane 代理的系统上。

获取 Google SecOps 客户 ID

  1. 登录 Google SecOps 控制台。
  2. 依次前往 SIEM 设置 > 个人资料
  3. 组织详细信息 部分复制并保存客户 ID

安装 Bindplane 代理

按照以下说明在 Windows 或 Linux 操作系统上安装 Bindplane 代理。

Windows 安装

  1. 以管理员身份打开命令提示符PowerShell
  2. 运行以下命令:

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    

Linux 安装

  1. 使用 root 或 sudo 权限打开终端。
  2. 运行以下命令:

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    

其他安装资源

如需了解其他安装选项,请参阅此安装指南

配置 Bindplane 代理以注入 Syslog 并发送到 Google SecOps

  1. 访问配置文件:

    • 找到 config.yaml 文件。通常,该文件位于 Linux 上的 /etc/bindplane-agent/ 目录或 Windows 上的安装目录中。
    • 使用文本编辑器(例如 nanovi 或记事本)打开该文件。
  2. 按如下方式修改 config.yaml 文件:

    receivers:
      udplog:
        # Replace the port and IP address as required
        listen_address: "0.0.0.0:514"
    
    exporters:
      chronicle/chronicle_w_labels:
        compression: gzip
        # Adjust the path to the credentials file you downloaded in Step 1
        creds_file_path: '/path/to/ingestion-authentication-file.json'
        # Replace with your actual customer ID from Step 2
        customer_id: YOUR_CUSTOMER_ID_HERE
        endpoint: malachiteingestion-pa.googleapis.com
        # Add optional ingestion labels for better organization
        log_type: 'ARUBA_IPS'
        raw_log_field: body
        ingestion_labels:
    
    service:
      pipelines:
        logs/source0__chronicle_w_labels-0:
          receivers:
            - udplog
          exporters:
            - chronicle/chronicle_w_labels
    
    • 根据基础架构中的需要替换端口和 IP 地址。
    • YOUR_CUSTOMER_ID_HERE 替换为实际的客户 ID。
    • /path/to/ingestion-authentication-file.json 更新为在第 1 步中保存身份验证文件的文件路径。
    • 更新 endpoint 值以与租户的区域匹配。

重启 Bindplane 代理以应用更改

  1. 如需在 Linux 中重启 Bindplane 代理,请运行以下命令:

    sudo systemctl restart observiq-otel-collector
    
  2. 如需在 Windows 中重启 Bindplane 代理,您可以使用服务 控制台,也可以输入以下命令:

    net stop observiq-otel-collector && net start observiq-otel-collector
    

在 Aruba 设备上配置 Syslog 转发

根据 Aruba 设备类型选择配置方法:

选项 A:Aruba 控制器 (AOS-8)

  1. 登录 Aruba 控制器 网页界面。
  2. 受管理网络 节点层次结构中,依次前往配置 > 系统 > 日志记录 > Syslog 服务器
  3. 如需添加日志记录服务器,请点击 Syslog 服务器 部分中的 +
  4. 提供以下配置详细信息:
    • 服务器 IP 地址:输入 Bindplane 代理 IP 地址。
    • 端口:输入 514(或在 Bindplane 中配置的端口)。
    • 协议:根据 Bindplane 代理配置,选择 UDPTCP
  5. 点击应用
  6. 如需选择要记录的消息类型,请选择日志记录级别
  7. 选择要记录的类别或子类别。
  8. 如需为类别或子类别选择严重程度,请从日志记录级别 下拉列表中选择级别。
  9. 格式 下拉列表中选择日志记录格式 CEFBSD 标准
    • 对于结构化日志记录,建议使用 ArcSight CEF (通用事件格式)。
  10. 点击提交
  11. 点击待处理的更改
  12. 待处理的更改 窗口中,选中复选框,然后点击部署更改

选项 B:Aruba Instant AP

使用网页界面

  1. 登录 Aruba Instant 网页界面。
  2. 在 Instant 主窗口中,点击系统 链接。
  3. 点击显示高级选项 以显示高级选项。
  4. 点击监控 标签页。
    • 系统会显示“监控”标签页的详细信息。
  5. 服务器 部分的 Syslog 服务器 文本框中,输入 Bindplane 代理的 IP 地址。
  6. Syslog Facility Levels 部分中,选择所需的值以配置 syslog facility levels。
    • Syslog 级别:有关 syslog 级别的详细日志。
    • AP-Debug:有关 Instant AP 设备的详细日志。
    • 网络:有关网络更改的日志,例如,向网络添加新的 Instant AP 时。
    • 安全:有关网络安全的日志,例如,客户端使用错误的密码进行连接时。
    • 系统:有关配置和系统状态的日志。
    • 用户:有关客户端的重要日志。
    • User-Debug:有关客户端的详细日志。
    • 无线:有关无线装置的日志。
  7. 点击 OK 以保存配置。

使用 CLI

  1. 登录 Aruba Instant AP CLI
  2. 进入配置模式:

    configure terminal
    
  3. 配置 syslog 服务器和级别:

    syslog-server <BINDPLANE_IP_ADDRESS>
    syslog-level warnings
    
    • <BINDPLANE_IP_ADDRESS> 替换为 Bindplane 代理主机的 IP 地址。
    • 根据需要调整严重程度。

选项 C:Aruba AOS-S(交换机)

  1. 登录 Aruba AOS-S 交换机 CLI
  2. 进入配置模式:

    configure
    
  3. 配置 syslog 服务器:

    logging <BINDPLANE_IP_ADDRESS>
    logging severity warnings
    
    • <BINDPLANE_IP_ADDRESS> 替换为 Bindplane 代理主机的 IP 地址。
    • 根据需要调整严重程度。
  4. 保存配置:

    write memory
    

选项 D:Aruba Central(本地)

  1. 登录 Aruba Central 网页界面。
  2. 依次前往系统 > 系统管理 > 通知 > Syslog 服务器
  3. 点击添加启用
  4. 提供以下配置详细信息:
    • 主机:输入 Bindplane 代理 IP 地址。
    • 端口:输入 514(或在 Bindplane 中配置的端口)。
    • 协议:根据 Bindplane 代理配置,选择 UDPTCP
    • Facility:根据需要选择 Local7 或其他选项。
    • 严重程度:选择最低日志级别(例如,警告信息)。
  5. 点击保存

UDM 映射表

日志字段 UDM 映射 逻辑
notifications.created_timestamp metadata.event_timestamp.seconds 原始日志字段 notifications.created_timestamp 会转换为秒并进行映射。纳秒在转换过程中会丢失。
notifications.customer_id metadata.product_log_id 直接映射。
notifications.device_id principal.resource.product_object_id 直接映射。
notifications.group_name principal.group.group_display_name 直接映射。
notifications.id metadata.product_log_id 直接映射。
notifications.timestamp metadata.event_timestamp.seconds 原始日志字段 notifications.timestamp 会转换为秒并进行映射。
rogue_aps.acknowledged security_result.detection_fields.value,其中 security_result.detection_fields.key 为“acknowledged” 转换为字符串并进行映射。
rogue_aps.containment_status metadata.description 直接映射。
rogue_aps.cust_id metadata.product_log_id 直接映射。
rogue_aps.encryption security_result.detection_fields.value,其中 security_result.detection_fields.key 为“encryption” 直接映射。
rogue_aps.first_det_device principal.resource.product_object_id 直接映射。
rogue_aps.first_det_device_name principal.hostname 直接映射。
rogue_aps.first_seen principal.domain.first_seen_time.seconds 解析为日期,并映射自 Epoch 以来的秒数。
rogue_aps.group_name principal.group.group_display_name 直接映射。
rogue_aps.id principal.mac 转换为小写并进行映射。
rogue_aps.labels security_result.detection_fields.value,其中 security_result.detection_fields.key 为“labels” 直接映射。
rogue_aps.last_det_device security_result.about.user.product_object_id 直接映射。
rogue_aps.last_det_device_name target.hostname 直接映射。
rogue_aps.last_seen principal.domain.last_seen_time.seconds 解析为日期,并映射自 Epoch 以来的秒数。如果存在,也用作事件时间戳。
rogue_aps.mac_vendor target.administrative_domain 直接映射。
rogue_aps.name target.user.userid 直接映射。
rogue_aps.overriden security_result.detection_fields.value,其中 security_result.detection_fields.key 为“overriden” 转换为字符串并进行映射。
rogue_aps.signal security_result.detection_fields.value,其中 security_result.detection_fields.key 为“signal” 转换为字符串并进行映射。
rogue_aps.ssid security_result.detection_fields.value,其中 security_result.detection_fields.key 为“ssid” 直接映射。
site principal.location.name 直接映射。
wids_aps_info_list.attack_type metadata.description 直接映射。
wids_aps_info_list.detected_ap principal.hostname 直接映射。
wids_aps_info_list.description security_result.description 直接映射。还用于使用 grok 提取多个字段。
wids_aps_info_list.event_time metadata.event_timestamp.seconds 转换为字符串,如果存在,则用作事件时间戳。
wids_aps_info_list.event_type metadata.product_event_type 直接映射。
wids_aps_info_list.macaddr principal.mac 转换为小写并进行映射。
wids_aps_info_list.radio_band security_result.detection_fields.value,其中 security_result.detection_fields.key 为“radio_band” 直接映射。
wids_aps_info_list.virtual_controller target.hostname 直接映射。如果 notifications.severity 为“Emergency”“Alert”或“Critical”,则设置为 true。如果 notifications.severity 为“Emergency”“Alert”或“Critical”,则设置为 true。由 events.event_typenotifications.type 字段确定,或默认设置为 GENERIC_EVENT。 多个映射派生自逻辑:STATUS_STARTUPSTATUS_SHUTDOWNSTATUS_UPDATEUSER_LOGINUSER_LOGOUT。始终设置为“ARUBA_IPS”。始终设置为“ARUBA_IPS”。始终设置为“ARUBA”。如果 events.event_type 为“Client DHCP Acknowledged”或“Client DHCP Timeout”,则设置为“DHCP”。如果 events.event_type 为“Client DHCP Acknowledged”或“Client DHCP Timeout”,则设置为“BOOTREPLY”。如果 events.event_type 为“Client DHCP Acknowledged”,则使用 grok 从 events.description 中提取。如果 events.event_type 为“Client DHCP Acknowledged”且 events.description 包含 IP 地址,则设置为“ACK”。否则,设置为“WIN_EXPIRED”。如果 events.event_type 以“Radio”“WLAN”“AP”开头或为“Security”,则设置为“ACCESS POINT”。如果 events.event_type 以“Radio”“WLAN”“AP”开头或为“Security”,则设置为“DEVICE”。对于大多数客户端事件,从 events.client_mac 映射;对于恶意 AP 事件,从 rogue_aps.last_det_device 映射。对于特定的 events.event_type 值,或如果 notifications.description 包含“DoS Attack”或“disconnect attack”,则设置为“AUTH_VIOLATION”。针对特定的 events.event_type 值设置。根据提取的字段(例如 bssidchannelprevious_channelssidprevious bssidacknowledgedoverridenencryptionsignallabelsradio_band)添加多个键值对。对于 wids 事件,从 wids_aps_info_list.description 映射。由 notifications.severitywids_aps_info_list.level 确定。对于 wids 事件,设置为“level: %{wids_aps_info_list.level}”。针对特定的 events.event_type 值设置。对于恶意 AP 事件,从 rogue_aps.mac_vendor 映射。对于恶意 AP 事件,从 rogue_aps.last_det_device_name 映射;对于 wids 事件,从 wids_aps_info_list.virtual_controller 映射。如果 events.event_type 为“Security”,则使用 grok 从 events.description 中提取。对于通知事件,从 notifications.client_mac 映射;对于客户端事件,从 events.client_mac 映射;对于 wids 事件,从 wids_aps_info_list.description 中提取的 target_mac 映射;对于恶意 AP 事件,从 rogue_aps.id 映射。对于大多数客户端事件,设置为“CLIENT”。对于大多数客户端事件,设置为“DEVICE”。如果 events.event_type 为“Security”,则设置为“ACTIVE”。对于恶意 AP 事件,从 rogue_aps.name 映射。
events.bssid security_result.detection_fields.value,其中 security_result.detection_fields.key 为“bssid” 直接映射。
events.client_mac target.mac 直接映射。还用于为客户端事件填充 security_result.about.user.product_object_id,为“Security”事件填充 target.ip
events.description metadata.description 对于 AP 和 Radio 事件,直接映射。对于其他事件类型,用于使用 grok 提取多个字段。
events.device_mac principal.mac 直接映射。
events.device_serial principal.resource.product_object_id 直接映射。
events.events_details.2.channel security_result.detection_fields.value,其中 security_result.detection_fields.key 为“channel” 直接映射。
events.group_name principal.group.group_display_name 直接映射。
events.hostname principal.hostname 直接映射。
events.timestamp metadata.event_timestamp.seconds 转换为字符串,移除毫秒,然后进行映射。如果存在,也用作事件时间戳。
timestamp metadata.event_timestamp 如果不存在其他时间戳字段,则用作事件时间戳。对于大多数客户端事件和“Security”事件,设置为“ACTIVE”。如果 events.event_type 为“Client 802.1x Radius Reject”,则设置为“AUTHTYPE_UNSPECIFIED”。如果 events.event_type 为“Security”,则使用 grok 从 events.description 中提取。

更新日志

查看此解析器的更新日志

需要更多帮助?获得社区成员和 Google SecOps 专业人士的解答。