RE: IIS and Snort

From: McCammon, Keith (Keith.McCammon@eadvancemed.com)
Date: 09/20/01


Message-ID: <BB7FD4FF9E440648A731452E5D341FB06545B5@hitsexchange01.advance-med.com>
From: "McCammon, Keith" <Keith.McCammon@eadvancemed.com>
To: 'Brian Carvalho' <brian.carvalho@verizon.net>, focus-ids@securityfocus.com
Subject: RE: IIS and Snort
Date: Wed, 19 Sep 2001 18:49:36 -0400


***Would Snort be a good choice for my application?

Yes!
 
***Are there specific Snort rulesets for IIS?

Yes. When you download the Snort distribution, it comes with a complete
ruleset for monitoring web, DNS, SQL, mail, etc. You can choose which rules
you wish to deploy.

***Is there any way to send alerts with Snort?

Snort generates an alert.ids file where alerts are written. However, you
can configure output plug-ins for SQL, syslog, etc. You can pretty much get
your alerts any way you want 'em with relatively little effort.

***Should I monitor on the actual server or from an admin
machine?

An admin machine. Set up a machine with two NIC's. One goes in promiscuous
mode on a switch monitoring port, and the other is for management. You
don't need a fast box, so don't worry about hardware cost. You can handle
T-3 speed with decent workstation (maybe less, maybe more, depending on
variables).



Relevant Pages

  • Re: 3rd Party IIS log analysis
    ... >>I'm currently in the market for a tool which analyzes IIS logs. ... There are some articles at http://online.securityfocus.com about using Snort ... There are a number of other affordable IDS devices and solutions that have ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS and Snort
    ... Subject: IIS and Snort ... Does anyone have any suggestions for generating email alerts from a unix box ... running snort which sends data to a mysql database. ...
    (Focus-IDS)
  • RE: Win32 Snort Question
    ... Website, in de FAQ about Snort, they expose some good links to that... ... If you try to use the network control panel Windows will complain that no IP ... >I would avoid putting firewall software on the machine as it might block ... >running IIS on the boxes to allow the ACID analysis tool to run. ...
    (Security-Basics)
  • RE: IIS and Snort
    ... Subject: IIS and Snort ... If you have more time then money, then OpenSnort is a great application. ... Snort takes time to setup and tune as well. ... I would like to setup some sort of IDS to monitor for this server. ...
    (Focus-IDS)
  • RE: IIS and Snort
    ... Subject: IIS and Snort ... look for a great win32 panel for snort called ... 'IDS Panel' ...
    (Focus-IDS)