Re: Newbie IDS questions

From: ndesai01@tampabay.rr.com
Date: 01/10/02


Date: 10 Jan 2002 01:01:53 -0000
From: <ndesai01@tampabay.rr.com>
To: focus-ids@securityfocus.com


('binary' encoding is not supported, stored as-is)

In-Reply-To: <9DCB77D01366AA4497DAFA759E1EB580BFAC33@WW1WEX01>

There are two ways that you can go that I know of. If
you have a limited budget then I would use hogwash.
This is a modified version of snort that is an inline
NIDS. The great thing about hogwash is that it is a
layer two device. It uses the same rules that snort
uses but has an additional action, drop.
If you need a commercially supported product
BlackICE (now part of ISS) makes a product called
Guard. This is the same type of device but with a
price. The main difference in the technologies is that
snort/hogwash are pattern matching NIDS were
BlackICE products are protocol analysis products.
There is good and bad to be said about both. If you
want to know more about protocol analysis NIDS look
up Robert Graham. He worked for Network General
developing Sniffer and then for NetworkICE. He has
the protocol analysis stuff down.

Neil



Relevant Pages

  • RE: "False positive" database idea
    ... snort config, I would love to be able to search such a database to see if I ... if someone really wants to use the bugzilla http API to automate their ... NIDS configuration, they deserve whatever Chad's scenario brings upon ... > Intrusion Prevention and Traffic Shaping Technology to: ...
    (Focus-IDS)
  • Re: OpenSource NIDS
    ... there are a number of other open source NIDS available. ... snort is production quality. ... > want to combine a signature based NIDS with a NIDS with strict anomaly ... There are input plugins, output ...
    (Focus-IDS)
  • Re: High availability design of NIDS
    ... I worked with snort, coupled with adodb, acid ... >> I am now designing an NIDS solution. ... >> both sensors can listen to all traffics in the network). ... But it runs under Linux. ...
    (Focus-IDS)
  • Re: [more specific] Signature vs. Protocol Analysis
    ... > that an analyst deploying a signature-based NIDS without customising the ... The most important signatures are going to be the ones ... the semantic equivalent of `dst host FOO and ... Then run Snort with the -o switch. ...
    (Focus-IDS)
  • "False postive" database idea
    ... own favorite "false positives". ... Why can't a public database of "false positive" be created so that NIDS ... that applies to NIDS with open sigs such as Snort and Dragon. ... conditions triggers snort 649 SHELLCODE sig. ...
    (Focus-IDS)