前言
近期 OpenClaw(小龙虾)在企业内部使用热度较高,部分员工自行安装并运行,存在较高的安全风险与合规隐患。
针对这一情况,根据领导决策,由安全组牵头制定办公网异常工具监控方案。结合当前环境,我优先推荐采用开源 IDS 解决方案 Suricata实现流量监控与行为检测,可实时识别内网中 OpenClaw 的安装、访问及外联行为,及时定位风险终端,保障办公网络安全。
Npcap的安装
Suricata 抓包依赖 Npcap(推荐,替代老旧 WinPcap)。
下载 Npcap:https://npcap.com/#download

安装:
- 勾选 Install Npcap in WinPcap API-compatible Mode(关键兼容)
- 勾选 Support loopback traffic(可选,方便本地测试)
- 完成后重启电脑
suricata的安装
下载全量安装包,打包好的二进制文件
访问https://www.openinfosecfoundation.org/download/windows/,下载最新的8.0.3版本的suricata

安装
点击双击Suricata-8.0.3-1-64bit.msi,直至安装完成
验证安装
cd C:\Program Files\Suricata
suricata.exe -v #查看版本

删除禁用不必要的文件
删除C:\Program Files\Suricata\rules下所有的rules

自定义规则
使用notepad--新建txt文件名为openclaw-detect.rules.txt,内容为
alert tcp $HOME_NET any -> any 18789 (msg:"OpenClaw Gateway 内网访问(18789)"; flow:established,to_server; classtype:policy-violation; sid:2000001; rev:1;)
alert tcp $HOME_NET any -> any 18789 (msg:"OpenClaw WebSocket 握手"; flow:established,to_server; content:"GET"; http.method; content:"/ws"; http.uri; content:"Upgrade: websocket"; http.header; content:"Connection: Upgrade"; http.header; classtype:policy-violation; sid:2000002; rev:1;)
alert tcp $HOME_NET any -> any 18789 (msg:"OpenClaw 公网暴露(18789)"; flow:established,to_server; classtype:trojan-activity; sid:2000003; rev:1;)
alert tcp $HOME_NET any -> any 18789 (msg:"OpenClaw 特征UA/关键词"; flow:established,to_server; content:"OpenClaw"; nocase; content:"ClawGateway"; nocase; classtype:policy-violation; sid:2000004; rev:1;)
alert tls $HOME_NET any -> any any (msg: "OpenClaw 官网访问";tls_sni; content:"openclaw.ai";nocase; flow:to_server;classtype:policy-violation;sid:2026031601; rev:1;)
alert tls $HOME_NET any -> any any (msg: "OpenClawAPI访问";tls_sni; content:"api.openclaw.ai";nocase;flow:to_server;classtype:policy-violation;sid:2026031602; rev:1;)
alert tls $HOME_NET any -> any any (msg: "OpenClaw文档访问";tls_sni; content:"docs.openclaw.ai";nocase;flow:to_server;classtype:policy-violation;sid:2026031603; rev:1;)
alert tls $HOME_NET any -> any any (msg: "有人访问了github上的OpenClaw";tls_sni; content:"github.com/openclaw";nocase; flow:to_server;classtype:policy-violation;sid:2026031604; rev
已在FreeBuf发表 0 篇文章
本文为 独立观点,未经授权禁止转载。
如需授权、对文章有疑问或需删除稿件,请联系 FreeBuf
客服小蜜蜂(微信:freebee1024)


