RE: snort- problems

From: Evans, Arian (Arian.Evans_at_fishnetsecurity.com)
Date: 08/06/03

  • Next message: Bennett Todd: "Re: IDS is dead, etc"
    Date: Wed, 6 Aug 2003 14:24:48 -0500
    To: "Rishi Pande" <rpande@vt.edu>, <focus-ids@securityfocus.com>
    
    

    Rishi,

    #I am new to security and IDS in general.

    Welcome. Panic and run away now if you can.

    #1) I was led to believe that Snort can run on one machine and monitor
    #specific IPs, which I would like to because not all machines on our
    #subnet are part of our office nor are they serially assigned. However,
    #snort is monitoring only the machine that it is installed on. Am i
    #missing something here or do I need another product?

    Snort, and any NIDS (network-based IDS) are essentially just like
    sniffers for the purpose of monitoring traffic.

    If you use hubs in your environment, every interface sees every packet,
    so you can simply plug a NIDS into a hub and see all the rest of the
    traffic on that hub...

    In a switched environment, unicast traffic only goes to the physical
    port on the switch that it's destination host is attached to. In that
    setup, you will only see (a) broadcast traffic and (b) traffic destined
    for your specific node/switch port.

    Most switches today have functionality to monitor traffic crossing the
    backplane of the switch. Some vendors call it a mirror port, some call
    it a monitor port, some call it a span port (Cisco). If you setup a span
    port, you can see all traffic crossing the backplane of that switch.

    Cisco also supports rspan, which allows you to remotely span *other*
    switches in your network from one port. I am not aware of any other
    switch vendors who do this (i.e.-someone asked this about Foundry
    earlier and they do not have this functionality yet).

    So if your network is switched, and your switch fabric is distributed
    at multiple sites, you are likely going to need more than one NIDS
    sensor (snort or otherwise) to monitor your environment. Even if
    you can rspan everything, the performance impact of doing this
    from remote sites will probably be a killer.

    Cheers,

    Arian Evans
    Sr. Security Engineer
    FishNet Security

    Phone: 816.421.6611
    Toll Free: 888.732.9406
    Fax: 816.421.6677

    http://www.fishnetsecurity.com

    The information transmitted in this e-mail is intended only for the addressee and may contain confidential and/or privileged material.
    Any interception, review, retransmission, dissemination, or other use of, or taking of any action upon this information by persons or entities
    other than the intended recipient is prohibited by law and may subject them to criminal or civil liability. If you received this communication
    in error, please contact us immediately at 816.421.6611, and delete the communication from any computer or network system.

    ---------------------------------------------------------------------------
    Captus Networks - Integrated Intrusion Prevention and Traffic Shaping
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
     - Automatically Control P2P, IM and Spam Traffic
     - Ensure Reliable Performance of Mission Critical Applications
    Precisely Define and Implement Network Security and Performance Policies
    **FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo
    Visit us at: http://www.captusnetworks.com/ads/31.htm
    ---------------------------------------------------------------------------


  • Next message: Bennett Todd: "Re: IDS is dead, etc"

    Relevant Pages

    • RE: rogue IP address
      ... Sorry if this seems like a dumb question, but you mentioned a "port to IP" ... Does your switch have a "port to MAC address table"? ... prospectus based upon the core principle concepts of security. ...
      (Security-Basics)
    • Re: Extender networking problem
      ... For both of you with problems, while a switch should work fine, ... switch and a D-Link 8 port that work fine. ... Do the router logs show any information about DHCP failures? ... >Security Log: No Events Reported ...
      (microsoft.public.windows.mediacenter)
    • Re: Richard... add-on Q: re XP Firewall;....
      ... > Isn't it somewhat self-serving for Symantec to warn ... > protect an individual port if this is indeed my ... When you run an on line security check you give specific permission to let ... you wish to respond to Pings you can always switch them back on. ...
      (microsoft.public.windowsxp.newusers)
    • RE: switch jamming
      ... The Cisco switch code for many of their switches allows the use of port ... security as mentioned below. ... The Cisco switches at least can be secured against this, ...
      (Vuln-Dev)
    • Re: Cat 2924
      ... Copyright 1986-2004 by cisco Systems, ... BOX in both H/W and S/W, compared to a C2924-XL Switch... ... FastEthernet0/1 failed front-end loopback test ... to make the port configuration "visible", you need to apply 2 commands ...
      (comp.dcom.sys.cisco)