Re: IDS evaluation

From: Frank Smith (fsmith@hoovers.com)
Date: 08/22/02


Date: Thu, 22 Aug 2002 11:35:40 -0500
From: Frank Smith <fsmith@hoovers.com>
To: Johannes Ullrich <jullrich@euclidian.com>, Saad Kadhi <bsdguy@docisland.org>


--On Thursday, August 22, 2002 12:25:41 -0400 Johannes Ullrich <jullrich@euclidian.com> wrote:

>> I'm a Snort fan but deploying 12 of them with central management needs
>> good expertise and multi-tool gluying skills.
>
> same here (snort fan). But I guess if you are comparing it to
> commercial products like Dragon, you should consider the
> commercial/supported version of snort from Sourcefire. I haven't
> had a chance to use it yet. But I understand they offer a central
> management console and a 'plug and play' appliance (hardware with
> pre-installed snort sensor).

Depending on the wheres and hows of your snort deployment, you might
want to look at the snort-mysql-acid combination for central reporting.

Frank



Relevant Pages

  • Re: IDS evaluation
    ... >>> I'm a Snort fan but deploying 12 of them with central management needs ... >> same here (snort fan). ... >> commercial products like Dragon, ... > Depending on the wheres and hows of your snort deployment, ...
    (Focus-IDS)
  • RE: IDS evaluation
    ... management console for multi-sensor SNORT signature management. ... > commercial products like Dragon, ...
    (Focus-IDS)
  • RE: dragon and snort logs
    ... > It is a fairly common occurrence for Enterasys customers to use snort. ... the time to write custom signatures for their existing IDS, ... with them to import those to Dragon, since Dragon is one of the few ... they are freely available on our support site. ...
    (Focus-IDS)
  • Re: Enterasys Dragon IDS for Unix/Linux
    ... Before I give a fully qualified response and properly point out ... its advantages over Snort, let me ask you this: ... $50,000 on Dragon, plus the time required to set up and run an IDS? ... you can, respond, and I'll give you the reasons I like Dragon, and the ...
    (comp.os.linux.security)
  • Re: Enterasys Dragon IDS for Unix/Linux
    ... Before I give a fully qualified response and properly point out ... its advantages over Snort, let me ask you this: ... $50,000 on Dragon, plus the time required to set up and run an IDS? ... you can, respond, and I'll give you the reasons I like Dragon, and the ...
    (comp.security.unix)