Reply
Highlighted
L2 Linker
Posts: 29
Registered: ‎02-10-2017
Accepted Solution

Zero indicators in inboundfeed

I am trying out minemeld and I started by adding miner (zeustracker.badips) and removing the default dshield and spam nodes. Before removal inbound feeds were showing subnet ranges/indicators. After removal there is not a single ip. processor shows RX count and PROCESSED count but output is all zero. Am i doing something wrong?

 

 

L4 Transporter
Posts: 115
Registered: ‎11-15-2012

Re: Zero indicators in inboundfeed

Hi @raji_toor,

 

you're facing an 'inbound' vs 'outbount' situation. Some threat intel feeds provide you with an attribute attached to the indicators meant to describe whether you should not connect to these IP's (outbound) or you should not accept connections from these IP's (inbound).

 

The dafault config include miners that attach the 'inbound' attribute to the indicators and an aggregator that enforces it. The following capture shows you the aggregator prototype: it accepts indicators of type IPv4 with attribute 'inbound' or 'null' and discards everything else.

 

2018-01-13_09-37-34.png

 

Now take a look to the Zeus Bad IP Prototype.

 

2018-01-13_09-40-32.png

 

 

As you can see, nodes based in this prototype will attach the outbound attribute to received indicators. And that will make the aggregator to discard them. If you take a look to the aggregator logs you'll find the discard action.

2018-01-13_09-43-37.png

 

 

You have many options:

  • Create a new prototype out of stdlib.aggregatorIPv4Inbound but removing the direction filter criteria (just accept type == 'IPv4')
  • Just use the aggregator stdlib.aggregatorIPv4Generic that is, in fact, what you'll achieve following the previous suggestion.
  • Create a new miner prototype out of zeustracker.badips but removing the direction attribute. That will make the indicators match because of the accep direction == 'null' filter action.
L2 Linker
Posts: 29
Registered: ‎02-10-2017

Re: Zero indicators in inboundfeed

Thanks @xhoms, That helped.

One more thing, i was able to follow this customizing minemeld article to copy and create a new miner in cli. But i also saw another article which shows a way of doing it in GUI, would you know how.

L4 Transporter
Posts: 115
Registered: ‎11-15-2012

Re: Zero indicators in inboundfeed

@raji_toor, follow examples like the Step 3 in the article MineMeld-Articles/Using-MineMeld-to-generate-IP-lists-from-wildcards to discover how to create new prototypes using the WEB UI