Outils pour utilisateurs

Outils du site


informatique:reseau:securite

Différences

Ci-dessous, les différences entre deux révisions de la page.

Lien vers cette vue comparative

Les deux révisions précédentesRévision précédente
Prochaine révision
Révision précédente
informatique:reseau:securite [18/05/2026 11:36] – [Lynis] cyrilleinformatique:reseau:securite [15/08/2026 11:34] (Version actuelle) – [Protection active] cyrille
Ligne 3: Ligne 3:
 ===== Documentation ===== ===== Documentation =====
  
-[[http://cwe.mitre.org|CWE - Common Weakness Enumeration]]: International in scope and free for public use, CWE™ provides a unified, measurable set of software weaknesses that is enabling more effective discussion, description, selection, and use of software security tools and services that can find these weaknesses in source code and operational systems as well as better understanding and management of software weaknesses related to architecture and design.\\ +CVE, CWE, CAPEC: [[/glossaire/MITRE]]
-http://cwe.mitre.org+
  
 [[/informatique/reseau/securite/traces_de_scan_bot_http]] [[/informatique/reseau/securite/traces_de_scan_bot_http]]
Ligne 14: Ligne 13:
 ===== Tests ===== ===== Tests =====
  
-PenTesting+PenTest -> Test d'intrusion 
  
 ===== Prestataires ===== ===== Prestataires =====
Ligne 26: Ligne 26:
   * http://www.dotsafe.fr/   * http://www.dotsafe.fr/
  
-===== Produits ===== 
- 
-[[http://www.hermitagesolutions.com/produits|Hermitage Solutions]] propose plein de produits de sécurité informatique, notamment l'IronKey, une clé USB avec chiffrement AES intégré. Il faut compter 69 €ht pour 1GB jusqu'à 276 €ht pour 16GB. 
  
 ===== Outils ===== ===== Outils =====
Ligne 51: Ligne 48:
  
 ==== Protection active ==== ==== Protection active ====
 +
 +Voir aussi [[/glossaire/waf|WAF (Web Application Firewall)]].
 +
 +==== ModSecurity ====
 +
 +ModSecurity est le moteur WAF open source historique.
 +
 +  * https://github.com/owasp-modsecurity/ModSecurity
 +
 +=== SafeLine ===
 +
 +SafeLine est un [[/glossaire/WAF]] open source.
 +
 +  * https://github.com/chaitin/safeline
 +
 +=== open-appsec ===
 +
 +open-appsec est un WAF open source basé sur l'apprentissage automatique, développé par Check Point.
 +
 +  * https://github.com/openappsec/openappsec
 +
 +=== Coraza ===
 +
 +OWASP Coraza est un moteur WAF moderne écrit en Go, entièrement compatible avec la syntaxe des règles ModSecurity et 100% compatible avec le Core Rule Set v4.
 +
 +  * https://github.com/corazawaf/coraza
 +
 +=== BunkerWeb ===
 +
 +BunkerWeb est une solution open source française qui repose sur Nginx et l'enrichit avec de nombreuses protections.
 +
 +  * https://www.bunkerweb.io/
 +  * https://www.it-connect.fr/tuto-bunkerweb-reverse-proxy-et-waf-open-source/
  
 === Floodmon === === Floodmon ===
Ligne 90: Ligne 120:
 http://www.zdziarski.com/projects/mod_evasive/ http://www.zdziarski.com/projects/mod_evasive/
  
-==== Blacklist ====+===== Blacklist =====
  
-=== Phishing and Malware Protection ===+==== Phishing and Malware Protection ====
  
 L'hameçonnage ou filoutage (phishing) est une technique de dissimulation d'adresse URL utilisée malhonnêtement pour tromper les internautes. L'hameçonnage ou filoutage (phishing) est une technique de dissimulation d'adresse URL utilisée malhonnêtement pour tromper les internautes.
Ligne 110: Ligne 140:
   * http://www.stopbadware.org   * http://www.stopbadware.org
  
-=== Spam protection ===+==== Spam protection ====
  
 http://www.rbl-watcher.com/list-rbl http://www.rbl-watcher.com/list-rbl
  
 +==== Listes IP/ASN malveillants ====
  
 +  * [[https://www.misp-project.org/feeds/|MISP (Malware Information Sharing Platform)]] 
 +    * https://www.misp-project.org/documentation/ 
 +    * Partage structuré d’informations sur les menaces (IOCs) entre organisations, avec contexte (tags, commentaires, liens entre événements) 
 +  * [[https://iplists.firehol.org/|FireHol]] 
 +    * https://www.firehol.org/ 
 +    * Fournir des listes de blocage optimisées pour les pare-feux (iptables, nftables, ipset) 
 +  * [[https://dataplane.org/signals.html|DataPlane]] 
 +    * Internet insight measured and monitored from over 300 nodes across 65 metropolitan areas on 6 continents. Signals are observed and discovered from our distributed network to provide unparalleled insight into anomalies and risks.
informatique/reseau/securite.1779096963.txt.gz · Dernière modification : de cyrille

Sauf mention contraire, le contenu de ce wiki est placé sous les termes de la licence suivante : CC0 1.0 Universal
CC0 1.0 Universal Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki