RE: TCP Dump Filters
From: McCammon, Keith (Keith.McCammon@eadvancemed.com)Date: 12/20/01
- Previous message: Whitt,Laura A.: "RE: Use of Taps for IDS"
- Maybe in reply to: JCFontelera@SolanoCounty.com: "TCP Dump Filters"
- Next in thread: Mark Coleman: "Re: TCP Dump Filters"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 20 Dec 2001 09:31:06 -0500 From: "McCammon, Keith" <Keith.McCammon@eadvancemed.com> To: <JCFontelera@SolanoCounty.com>, <focus-ids@securityfocus.com>
You can do a search for BPF syntax (man tcpdump), but tcpdump is not
intended, nor is it optimized, for use as an intrusion detection system.
You can create very restrictive filters, and even decode application
data and output it to a database, but in the end (analysis, matching,
and alerting) you're just re-inventing the wheel.
Snort (http://www.snort.org), on the other hand, is exactly what you're
looking for!
Cheers
Keith
-----Original Message-----
From: JCFontelera@SolanoCounty.com [mailto:JCFontelera@SolanoCounty.com]
Sent: Wednesday, December 19, 2001 7:26 PM
To: focus-ids@securityfocus.com
Subject: TCP Dump Filters
Does anyone know a good web site that explains how
to create TCPDUMP or windump filters to detect all sorts of
attack signatures ?
Thanks,
Jaime
- Previous message: Whitt,Laura A.: "RE: Use of Taps for IDS"
- Maybe in reply to: JCFontelera@SolanoCounty.com: "TCP Dump Filters"
- Next in thread: Mark Coleman: "Re: TCP Dump Filters"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|