SiLK 2.3.1
SiLK, the System for Internet-Level Knowledge, is a collection of
traffic analysis tools developed by the CERT Network Situational
Awareness Team (CERT NetSA) to facilitate security analysis of large
networks. The SiLK tool suite supports the efficient collection,
storage, and analysis of network flow data, enabling network security
analysts to rapidly query large historical traffic data sets. SiLK is
ideally suited for analyzing traffic on the backbone or border of a
large, distributed enterprise or mid-sized ISP.
A SiLK installation consists of two categories of applications: the
packing system and the analysis suite. The packing system collects
IPFIX, NetFlow v9, or NetFlow v5 and converts the data into a more
space efficient format, recording the packed records into
service-specific binary flat files. The analysis suite consists of
tools which read these flat files and perform various query
operations, ranging from per-record filtering to statistical analysis
of groups of records. The analysis tools interoperate using pipes,
allowing a user to develop a relatively sophisticated query from a
simple beginning.
Signed-off-by: Adam Vandenberg <flangy@gmail.com>
2010-06-11 01:45:37 +00:00
|
|
|
require 'formula'
|
|
|
|
|
2011-03-10 05:11:03 +00:00
|
|
|
class Silk < Formula
|
2010-11-07 18:59:18 +00:00
|
|
|
url 'http://tools.netsa.cert.org/releases/silk-2.4.0.tar.gz'
|
SiLK 2.3.1
SiLK, the System for Internet-Level Knowledge, is a collection of
traffic analysis tools developed by the CERT Network Situational
Awareness Team (CERT NetSA) to facilitate security analysis of large
networks. The SiLK tool suite supports the efficient collection,
storage, and analysis of network flow data, enabling network security
analysts to rapidly query large historical traffic data sets. SiLK is
ideally suited for analyzing traffic on the backbone or border of a
large, distributed enterprise or mid-sized ISP.
A SiLK installation consists of two categories of applications: the
packing system and the analysis suite. The packing system collects
IPFIX, NetFlow v9, or NetFlow v5 and converts the data into a more
space efficient format, recording the packed records into
service-specific binary flat files. The analysis suite consists of
tools which read these flat files and perform various query
operations, ranging from per-record filtering to statistical analysis
of groups of records. The analysis tools interoperate using pipes,
allowing a user to develop a relatively sophisticated query from a
simple beginning.
Signed-off-by: Adam Vandenberg <flangy@gmail.com>
2010-06-11 01:45:37 +00:00
|
|
|
homepage 'http://tools.netsa.cert.org/silk/'
|
2010-11-07 18:59:18 +00:00
|
|
|
md5 '3c12579712e2f49b07e56055a209d20a'
|
SiLK 2.3.1
SiLK, the System for Internet-Level Knowledge, is a collection of
traffic analysis tools developed by the CERT Network Situational
Awareness Team (CERT NetSA) to facilitate security analysis of large
networks. The SiLK tool suite supports the efficient collection,
storage, and analysis of network flow data, enabling network security
analysts to rapidly query large historical traffic data sets. SiLK is
ideally suited for analyzing traffic on the backbone or border of a
large, distributed enterprise or mid-sized ISP.
A SiLK installation consists of two categories of applications: the
packing system and the analysis suite. The packing system collects
IPFIX, NetFlow v9, or NetFlow v5 and converts the data into a more
space efficient format, recording the packed records into
service-specific binary flat files. The analysis suite consists of
tools which read these flat files and perform various query
operations, ranging from per-record filtering to statistical analysis
of groups of records. The analysis tools interoperate using pipes,
allowing a user to develop a relatively sophisticated query from a
simple beginning.
Signed-off-by: Adam Vandenberg <flangy@gmail.com>
2010-06-11 01:45:37 +00:00
|
|
|
|
2010-11-07 18:59:18 +00:00
|
|
|
depends_on 'pkg-config' => :build
|
SiLK 2.3.1
SiLK, the System for Internet-Level Knowledge, is a collection of
traffic analysis tools developed by the CERT Network Situational
Awareness Team (CERT NetSA) to facilitate security analysis of large
networks. The SiLK tool suite supports the efficient collection,
storage, and analysis of network flow data, enabling network security
analysts to rapidly query large historical traffic data sets. SiLK is
ideally suited for analyzing traffic on the backbone or border of a
large, distributed enterprise or mid-sized ISP.
A SiLK installation consists of two categories of applications: the
packing system and the analysis suite. The packing system collects
IPFIX, NetFlow v9, or NetFlow v5 and converts the data into a more
space efficient format, recording the packed records into
service-specific binary flat files. The analysis suite consists of
tools which read these flat files and perform various query
operations, ranging from per-record filtering to statistical analysis
of groups of records. The analysis tools interoperate using pipes,
allowing a user to develop a relatively sophisticated query from a
simple beginning.
Signed-off-by: Adam Vandenberg <flangy@gmail.com>
2010-06-11 01:45:37 +00:00
|
|
|
depends_on 'glib'
|
|
|
|
depends_on 'libfixbuf'
|
|
|
|
depends_on 'yaf'
|
|
|
|
|
2011-03-21 21:24:22 +00:00
|
|
|
fails_with_llvm "Undefined symbols during compile"
|
2010-08-18 20:41:52 +00:00
|
|
|
|
2011-03-21 21:24:22 +00:00
|
|
|
def install
|
2010-04-07 05:58:35 +00:00
|
|
|
system "./configure", "--disable-dependency-tracking",
|
|
|
|
"--prefix=#{prefix}",
|
|
|
|
"--mandir=#{man}",
|
|
|
|
"--enable-ipv6",
|
|
|
|
"--enable-data-rootdir=#{var}/silk"
|
SiLK 2.3.1
SiLK, the System for Internet-Level Knowledge, is a collection of
traffic analysis tools developed by the CERT Network Situational
Awareness Team (CERT NetSA) to facilitate security analysis of large
networks. The SiLK tool suite supports the efficient collection,
storage, and analysis of network flow data, enabling network security
analysts to rapidly query large historical traffic data sets. SiLK is
ideally suited for analyzing traffic on the backbone or border of a
large, distributed enterprise or mid-sized ISP.
A SiLK installation consists of two categories of applications: the
packing system and the analysis suite. The packing system collects
IPFIX, NetFlow v9, or NetFlow v5 and converts the data into a more
space efficient format, recording the packed records into
service-specific binary flat files. The analysis suite consists of
tools which read these flat files and perform various query
operations, ranging from per-record filtering to statistical analysis
of groups of records. The analysis tools interoperate using pipes,
allowing a user to develop a relatively sophisticated query from a
simple beginning.
Signed-off-by: Adam Vandenberg <flangy@gmail.com>
2010-06-11 01:45:37 +00:00
|
|
|
system "make"
|
|
|
|
system "make install"
|
|
|
|
|
|
|
|
(var+"silk").mkpath
|
|
|
|
end
|
|
|
|
end
|