What is Snort?
Snort is an open source network intrusion detection system (NIDS) that can audit network traffic in real-time. Snort is a packet sniffer, a packet logger, and a network intrusion detection system.
Snort as I mentioned before is an open source software which means it can be configured and complied on most operating systems. Snort has been ported over to Microsoft Windows operating systems also, but it's bread and butter is back on the UNIX/Linux side of the house. Most Linux distributions now include Snort as part of their install package, and though it may not be enabled by default, normally it is on the installation CD's or DVD's.
Should I run Snort if I have a firewall?
I believe that yes you should run a NDIS even with a firewall. Firewalls help to block packets coming in to your system, however if you are running different servers or services that require the firewall to let them through you are letting a large amount of data go un-audited. Snort has the ability to see trends in incoming data and identify them as a threat and take appropriate action on your system. Snort gives you the ability to see if you are being port scanned, or to see if someone is trying to abuse well known backdoors or problems in well known daemons. Running services and applications that help you to protect your system is always a good idea. Many system administrators run a firewall, snort, and a data file integrity checker (often Tripwire).
How does snort actually work?
Snort generally is running as a background application and it is constantly packet sniffing all the information passing through your network interface card (NIC). The data is then sorted by various preprocessors that basically sort the packet data in to different categories. Once the data has been sorted out it is run through the rules, or the detection phase. As Snort detects trends in the data it applies the rules and actions them appropriately. The final stages are logging the rule infractions and if configured alerting the system administration team in real-time as the infraction occurs.
Is Snort difficult to configure and use?
Snort, as mentioned before now often comes bundled or available through rpm's in most Linux distributions. The hard part of running snort is if you decide to create your own original rules which can get extremely complex. However, luckily for us you can download up to date rule sets for free off the Snort website (you must signup for the free registration).
For extra ease of use there are many different applications and log parsers which have been designed to work with Snort. These applications can create websites based on the data Snort has logged or help you identify trends or possibly security threats on your system.
Ken Dennis
http://kendennis-rss.homeip.net/
Microsoft Business Solutions Great Plains is Dexterity-written application and currently... Read More
Spyware and Adware infest over 90 percent of computers in... Read More
It???s easy to understand why you might be drawn to... Read More
No matter how much you enjoy your favorite screensavers, sometimes... Read More
Microsoft Great Plains is main mid-market application from Microsoft Business... Read More
You would like to protect your documents, wouldn't you? Reasons... Read More
Have you ever noticed that when you look at your... Read More
Spyware, what it is and what it does. Basically, spyware... Read More
C++ Function templates are those functions which can handle different... Read More
We all already got used to computer monitoring both at... Read More
Passwords protect your most sensitive personal, financial and business information.... Read More
If you are in the market for new staffing software,... Read More
Background: For many organizations like ours, the interim target of... Read More
Microsoft Business Solutions CRM data conversion deserves FAQ type of... Read More
IntroductionPHP can be used for a lot of different things,... Read More
Just when you thought you were Web savvy, one more... Read More
If you have Microsoft Great Plains and support it for... Read More
Microsoft Great Plains and Microsoft Retail Management System (Microsoft RMS)... Read More
Microsoft Great Plains could be tuned and setup to fit... Read More
Most people understand that the "hardware" part of their computer... Read More
Microsoft Business Solutions ? Great Plains is designed to meet... Read More
Microsoft SQL Server is the leader for inexpensive and middle... Read More
Formatting and reinstalling windows 98 is very easy if you... Read More
Every organization which creates collaborative documents, whether they are budgets,... Read More
The various resume software offered, particularly on the internet, can... Read More
limo O'Hare Bonfield ..FTP stands for "file transfer protocol". FTP is basically a... Read More
ERP Consulting industry is on the way to serve clients... Read More
.NET platform does not support multiple inheritance. Do not confuse... Read More
Microsoft CRM and IBM Lotus Notes Domino seem to be... Read More
When you need a phone number, you do a quick... Read More
1. With mapping software you can create a report that... Read More
Microsoft CRM is CRM answer from Microsoft Business Solutions. If... Read More
Does Microsoft Have any Real Competition? Copyright (c) 2003 Gregory... Read More
Are you one of those people that keeps track of... Read More
Once a business idea is selected, it is highly recommended... Read More
The Windows registry is a huge database that ensures normal... Read More
Security flaws have long plagued Internet Explorer (IE), the market-dominating... Read More
Let's first look at your ERP system selection (without Retail... Read More
Spyware and Adware infest over 90 percent of computers in... Read More
The Software 2005 conference is now a wrap. This conference,... Read More
ERP is the acronym of Enterprise Resource Planning. Multi-module ERP... Read More
DBxtra is a powerful query and reporting tool that hides... Read More
In linux, one of great commands for finding out information... Read More
It is a well known fact that Java as a... Read More
Microsoft CRM is now on the scene and it is... Read More
Microsoft-Outlook is a pretty amazing program. So much more than... Read More
Your computer cost you from hundreds to thousands of dollars,... Read More
While paper labeling CDs and DVDs may appear to be... Read More
Almost all new and major brand of PCs come with... Read More
It???s easy to understand why you might be drawn to... Read More
Software |