Trisul – Sourceforge and Google Code setup

fetch.png

Project Hosting

Trisul is a new open source project that is targeted at security analysts. I set up both Google Code and Sourceforge project sites. As much as I like SF, its performance leaves a lot to be desired. It also loads a lot of external content which adds to its load time. I will use the issue tracker and download link on Google Code. Perhaps as the project matures, we can revisit Sourceforge.

Blog

I also created a wordpress blog called trisul.wordpress.com

Domain

I purchased the domain trisul.org. Eventually, the project will move there. We probably need a VPS if we want to host a demo of Web Trisul (the Ruby on Rails web frontend to the network metering data)

Todo List

Just playing with some options here. I quickly checked out tadalist and todoist. I could not find an easy way to publicly share list items on todoist, so I chose tadalist. The public tasks page is here

New code

The first release on sourceforge (0.4.116) was an embarassing mess. This was due to my unfamiliarity with autoconf and friends. I had just zipped up the source directory as a tarball instead of “make distcheck”. The new release takes care of that.

————————————————–

Some questions people ask me about Trisul. I will try to answer them in the next blog post.

1) Is this project too ambitious ? Can one system integrate traffic monitoring, raw data recording, session tracking, and forensics ?

2) When good stuff like SANCP, Time Machine, ntop, argus, are already available – what beverage is Trisul bringing to the party ?

3) Trisul is at best a single “sensor” or “observation point”, how does it plan to integrate into a centralized console like SGUIL etc.

 

Announcing Trisul

We are happy to announce a major new open source project called Trisul.

fetch.png

What is Trisul ?

Trisul is a network metering and forensics tool. You can install Trisul on any Linux box and have it look at network traffic in real time or via capture files. It meters the traffic (by host, by protocol, by subnet, etc) and stores the results in a SQL database. Trisul also includes a Ruby on Rails application called Web Trisul that allows you to use a web browser to view data in the form of pretty charts.

Status

Trisul has been in development for a few months now primarily as a remote probe for the upcoming Unsniff 2.0 release. We decided to make it open source once we cleaned up some embarassing bits of code. The entire software is GPLv3.

You can install Trisul right away and do some really useful stuff with it. It is still rough around the edges in terms of documentation and the occasional stability problem.

Get it !

We encourage all network administrators especially those involved in security operations to try out Trisul. 

The Trisul Project Site

Trisul Sourceforge Download Page

 

Cisco SNMP MIB Package updated

The latest Cisco SNMP MIBs from their FTP site is now available as a Unbrowse SNMP MIB Package. This is the easiest way to work with Cisco equipment using SNMP. This monster package consists of 1082 MIB modules and over 70,000 unique objects.

This package can be installed via one click via “Repository -> Import Package”

Download the package from here.

Download Unbrowse SNMP from here.