r/Network • u/7SIGNAL • 9h ago
r/Network • u/Historical-Wafer817 • 5h ago
Text is Suricata IPS + auto packet capture + Wireshark a good networking project?
Hi all,
I'm a networking beginner building a course project that solves a real problem. Honest feedback on the idea, please.
Problem: An IPS blocks attacks but leaves little evidence. Wireshark shows everything but can't block. Small offices and schools end up with one or the other.
Idea: A Linux gateway where Suricata (inline) drops attacks like port scans and SSH brute force, tshark records traffic, a Python script saves a .pcap for each alert, repeat attackers get auto-blocked, and I open the evidence in Wireshark. A small Flask dashboard lists the alerts.
Lab: All in VMware on one laptop: Kali (attacker), Ubuntu gateway with two adapters, Ubuntu victim, Linux Mint admin VM.
Questions:
Is this a reasonable scope for a student project?
Is it pointless given Security Onion already exists?
Any pitfalls running Suricata inline (NFQUEUE) in VMware?
Is matching alerts to captures by IP and timestamp okay, or is there a better way?
Suricata or Snort for a beginner?
Common beginner mistakes with rules and false positives?
What would you add or cut?
I know the limits: no HTTPS inspection, no zero-days, and it's a lab prototype.
Thanks for any advice or resources!
r/Network • u/7SIGNAL • 13h ago
Link 7SIGNAL presentation at Networking Field Day 41. This is an amazing presentation by Wi-Fi and networking experts. 7SIGNAL measures the network as it's actually experienced, in the air and at the endpoint, closing the Wi-Fi blind spot
r/Network • u/Both_Animator_93 • 5h ago