Software Information

Snort for Network IDS


Home | Site Map | 101InfoLinks.com | Best Book Shop | Sports Fans ONLY
     .
© 2007

What is Snort?

Snort is an open source network intrusion detection system (NIDS) that can audit network traffic in real-time. Snort is a packet sniffer, a packet logger, and a network intrusion detection system.

Snort as I mentioned before is an open source software which means it can be configured and complied on most operating systems. Snort has been ported over to Microsoft Windows operating systems also, but it's bread and butter is back on the UNIX/Linux side of the house. Most Linux distributions now include Snort as part of their install package, and though it may not be enabled by default, normally it is on the installation CD's or DVD's.

Should I run Snort if I have a firewall?

I believe that yes you should run a NDIS even with a firewall. Firewalls help to block packets coming in to your system, however if you are running different servers or services that require the firewall to let them through you are letting a large amount of data go un-audited. Snort has the ability to see trends in incoming data and identify them as a threat and take appropriate action on your system. Snort gives you the ability to see if you are being port scanned, or to see if someone is trying to abuse well known backdoors or problems in well known daemons. Running services and applications that help you to protect your system is always a good idea. Many system administrators run a firewall, snort, and a data file integrity checker (often Tripwire).

How does snort actually work?

Snort generally is running as a background application and it is constantly packet sniffing all the information passing through your network interface card (NIC). The data is then sorted by various preprocessors that basically sort the packet data in to different categories. Once the data has been sorted out it is run through the rules, or the detection phase. As Snort detects trends in the data it applies the rules and actions them appropriately. The final stages are logging the rule infractions and if configured alerting the system administration team in real-time as the infraction occurs.

Is Snort difficult to configure and use?

Snort, as mentioned before now often comes bundled or available through rpm's in most Linux distributions. The hard part of running snort is if you decide to create your own original rules which can get extremely complex. However, luckily for us you can download up to date rule sets for free off the Snort website (you must signup for the free registration).

For extra ease of use there are many different applications and log parsers which have been designed to work with Snort. These applications can create websites based on the data Snort has logged or help you identify trends or possibly security threats on your system.

Ken Dennis
http://KenDennis-RSS.homeip.net/


MORE RESOURCES:

PC World

At CES, Microsoft Introduces the Unexpected: Songwriting Software
PC World - 1 hour ago
The software itself, though, appears legit and pretty straightforward. You choose a style (per the screen above), then a tempo, and then there's a main ...
Microsoft on song with music software Inquirer
Microsoft releases SongSmith: Karaoke in reverse CNET News
Microsoft Research discovers its inner Songsmith BetaNews
Seattle Times - PR Newswire (press release)
all 30 news articles


The Age

Test Drive the latest software with the Microsoft Action Pack ...
CRN, NY - 3 hours ago
Get the latest Microsoft® software, tools, training, and business-critical support at an affordable cost to help you close more sales, ...
Microsoft could announce free software upgrades at Consumer ... Telegraph.co.uk
Steve Ballmer's Rally Cry Forbes
Microsoft begins Windows 7 push BBC News
Reuters - ComputerWeekly.com
all 985 news articles


Ars Technica

Vietnam pushes open-source software for government use
NetworkWorld.com, MA - 6 hours ago
By the end of 2009, 70 percent of the workstations in local state agencies should have the software installed, with 40 percent of employees proficient in ...
Vietnam mandates 100 percent open source by 2010 CNET News
Vietnam mandates government adoption of open source Ars Technica
Vietnamese government mandates Open Source Inquirer
Slashdot - p2pnet.net
all 14 news articles


Expo: Paragon Software releases ‘talking’ dictionaires for OS X
Macworld, CA - 8 hours ago
by Dale Roe, Macworld.com Paragon Software released 30 SlovoEd “talking” dictionaries for the Mac OS this week at Macworld Expo. ...


Acresso Software Finalizes Intraware Acquisition
CNNMoney.com - 21 hours ago
Acresso Software (Acresso), a privately-held company and an investment of private equity firm Thoma Bravo, LLC, announced today it has completed the ...


guardian.co.uk

Apple unveils software updates, new laptop
San Francisco Chronicle,  USA - Jan 7, 2009
The presentation included updates to the iLife and iWork software suites, a new 17-inch MacBook Pro with an 8-hour battery and a new digital rights ...
Video: Steve Jobs Weight Loss Due to Hormone Imbalance AssociatedPress
Macworld goes for the soft sell with budget-minded software USA Today
Apple's Macworld Surprise Is the Software PC Magazine
Macworld - The Associated Press
all 2,742 news articles


Earthtimes (press release)

IBM Lotus Delivers New "Social" Notes and Free Symphony Software ...
CNNMoney.com - Jan 6, 2009
At Macworld, IBM (NYSE: IBM) today announced the availability of Lotus Notes 8.5 collaboration software with social computing features for all Mac OS X ...
IBM Polishes Its Apple Offerings Forbes
Macworld: IBM finalizing free Symphony office suite for Macs Computerworld
Lotus Notes 8.5 ships, free IBM Symphony suite coming MacNN
ZDNet Blogs - VNUNet.com
all 59 news articles


CNET News

Sun Acquires Cloud Computing Software Supplier, Q-Layer
InformationWeek, NY - 14 hours ago
The Belgian company makes data center modeling and management software that helps companies organize their computing resources as a cloud computing layer. ...
Sun Acquires Cloud Computing Automator Q-layer eWeek
Sun Buys Cloud-computing Vendor Q-layer PC World
Sun acquires cloud computing vendor ZDNet
TheStreet.com - ITProPortal
all 98 news articles


ABC News

ITunes embraces 3-tier pricing, will remove anti-copy software
Los Angeles Times, CA - Jan 6, 2009
Apple also updated much of its software. The latest version of iPhoto scans for individual faces so computer users can label photos of friends or family, ...
Apple Unveils Software, MacBook At Macworld CNNMoney.com
Apple rolls out 17-inch MacBook Pro, new software, iTunes Store tweaks DVICE
Apple updates iTunes, iLife, unveils 17-inch MacBook Bizjournals.com
TourDates.Co.Uk - Motley Fool
all 1,357 news articles


MacNN

Autodesk offers three new Mac creative software tools
Macworld, CA - 21 hours ago
by Peter Cohen, Macworld.com Autodesk, which is not participating in Macworld Expo this week, introduced three new creative software tools for the Mac ...
Autodesk releases Toxik, Mudbox, Stitcher for Mac MacNN
Autodesk adds Mac versions of Toxik, Mudbox and ImageModeler 2009 Digital Arts Online
all 35 news articles

Software - Google News


Google
 

Home | Site Map | 101InfoLinks.com | Best Book Shop | Sports Fans ONLY
     .
© 2007