Traffic Analysis in Qubes OS

Original forum link
https://forum.qubes-os.org/t/18886
Original poster
taradiddles
Editors
deeplow
Created at
2023-05-26 14:49:49
Last wiki edit
2023-08-14 20:28:59
Revisions
2 revisions
Posts count
1
Likes count
0
Tags
external, networking, security

https://zrubi.hu/en/2017/traffic-analysis-qubes/

Excerpt:

[quote] One of the best thing in Qubes OS that you can use special type of VMs called ProxyVM (or FirewallVM). The special thing is that your AppVMs see this as a NetVM, and the NetVMs see it as an AppVM.

Because of that You can place a ProxyVM between your AppVMs and Your NetVM. This way we can create an ideal topology for traffic analysis. One of the best applications for such task is Suricata. The free and open source, mature, fast and robust network threat detection engine. The Suricata engine is capable of real time intrusion detection (IDS), inline intrusion prevention (IPS), network security monitoring (NSM) and offline pcap processing – however this article only covers the Qubes integration of this product. [/quote]