Software Information

Snort for Network IDS


What is Snort?

Snort is an open source network intrusion detection system (NIDS) that can audit network traffic in real-time. Snort is a packet sniffer, a packet logger, and a network intrusion detection system.

Snort as I mentioned before is an open source software which means it can be configured and complied on most operating systems. Snort has been ported over to Microsoft Windows operating systems also, but it's bread and butter is back on the UNIX/Linux side of the house. Most Linux distributions now include Snort as part of their install package, and though it may not be enabled by default, normally it is on the installation CD's or DVD's.

Should I run Snort if I have a firewall?

I believe that yes you should run a NDIS even with a firewall. Firewalls help to block packets coming in to your system, however if you are running different servers or services that require the firewall to let them through you are letting a large amount of data go un-audited. Snort has the ability to see trends in incoming data and identify them as a threat and take appropriate action on your system. Snort gives you the ability to see if you are being port scanned, or to see if someone is trying to abuse well known backdoors or problems in well known daemons. Running services and applications that help you to protect your system is always a good idea. Many system administrators run a firewall, snort, and a data file integrity checker (often Tripwire).

How does snort actually work?

Snort generally is running as a background application and it is constantly packet sniffing all the information passing through your network interface card (NIC). The data is then sorted by various preprocessors that basically sort the packet data in to different categories. Once the data has been sorted out it is run through the rules, or the detection phase. As Snort detects trends in the data it applies the rules and actions them appropriately. The final stages are logging the rule infractions and if configured alerting the system administration team in real-time as the infraction occurs.

Is Snort difficult to configure and use?

Snort, as mentioned before now often comes bundled or available through rpm's in most Linux distributions. The hard part of running snort is if you decide to create your own original rules which can get extremely complex. However, luckily for us you can download up to date rule sets for free off the Snort website (you must signup for the free registration).

For extra ease of use there are many different applications and log parsers which have been designed to work with Snort. These applications can create websites based on the data Snort has logged or help you identify trends or possibly security threats on your system.

Ken Dennis
http://KenDennis-RSS.homeip.net/


MORE RESOURCES:

Los Angeles Times

Software for supervising students
Los Angeles Times, CA - 3 hours ago
Here's an overview of some of the more popular programs: MealpayPlus: A program from Horizon Software International that lets parents go online to put money ...
Online tools let parents peer into their kids' school day Los Angeles Times
all 3 news articles


ABC News

Open Sauce Software
ZDNet UK, UK - 49 minutes ago
Chrome is still my default browser, and there are everyday things I can't do so easily in it as in Firefox. Perversely. I think what I want is a Google ...
Video: Tech Test: Google Chrome Lacks Polish AssociatedPress
Google Chrome: A Hit with Online Software Vendors CIO
How will Google Chrome change the user experience on the web? CNET News
Reuters - InformationWeek
all 3,424 news articles


Lieberman Software Launches Virtual Server Management Initiative
MarketWatch - 21 hours ago
LOS ANGELES, Sep 04, 2008 (BUSINESS WIRE) -- Lieberman Software's User Manager Pro Suite, a configuration management solution for Windows-powered servers ...
Vendors scramble to rein in virtual environments NetworkWorld.com
Azaleos' OneServer Now Supports Microsoft Hyper-V Server TMCnet
Hyper-V Virtual Monitoring Appliance Debuts at Microsoft Conference WebWire (press release)
MarketWatch
all 23 news articles


Sun to Craft Software Stack Into NAS Appliances
PC World - 9 hours ago
Sun Microsystems will introduce a storage appliance based on its FISHworks software package by the end of this year and later extend the technology to other ...


Roper Industries buys Horizon Software
Bizjournals.com, NC - 15 hours ago
Horizon, based in Duluth, Ga., will continue to market its products and services under its current brand names and will become part of Roper’s radio ...
Roper Acquires Horizon Software, Expands K-12 Business with Food ... Education Channel Partner
Lakewood Ranch company acquires software player Sarasota Herald-Tribune
Roper Industries Acquires Horizon Software International MarketWatch
SunHerald.com
all 14 news articles


Check Point Software Shareholders Approve all Proposals at 2008 ...
MarketWatch - 11 hours ago
Check Point Software Technologies Ltd. ( www.checkpoint.com) is the leader in securing the Internet. Check Point offers total security solutions featuring a ...


Arxan Hosts Complimentary Webinar on Software Protection Best ...
PR Web (press release), WA - 2 hours ago
What application hardening and software protection best practices can be put to use so companies can take back control of their applications and revenues. ...


Schools Consider Software Update
Tampa Tribune, FL - 6 hours ago
By RONNIE BLAIR LAND O' LAKES - The Pasco County School District is considering replacing its outdated computer software with something new that could ...


Software engineering degree coming to SUNY Oswego
NewsChannel 9 WSYR, NY - 6 hours ago
Oswego, New York (WSYR-TV) – Central New York students looking to major in software engineering now have a cheaper, closer option to choose from. ...
Software Added SUNY Oswego
all 2 news articles


American Software Q1 Earnings Drop As Revenues Decline - Update
RTT News, NY - 10 hours ago
Software license revenues were $2.7 million, down 46% from $5.1 million in the prior-year quarter. AMSWA ended Thursday's regular trading at $5.79, ...
MOST E-MAILED RTT News
all 3 news articles

Software - Google News

home | site map
© 2006