Skip to content

Deploy Zeek network monitoring #14

@bondlegend4

Description

@bondlegend4

Global ID: VICS-BACKEND-003


Estimated Time: 3-4 days

Problem

Need network traffic monitoring and anomaly detection for ICS protocols (Modbus TCP).

Solution Tasks

  • Deploy Zeek (formerly Bro) in container
  • Configure Zeek to monitor OT network segment
  • Enable Modbus TCP protocol analyzer
  • Set up logging to persistent volume
  • Create baseline traffic profiles
  • Configure anomaly detection rules
  • Integrate alerts with Godot frontend
  • Document log analysis procedures

Acceptance Criteria

  • Zeek captures all OT network traffic
  • Modbus TCP transactions logged correctly
  • Baseline profiles established
  • Anomalies trigger alerts
  • Logs accessible for forensics
  • Performance impact < 5% network throughput

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions