New to Snort !!!

From: Venkatesh G S (venkatesh.gs_at_gmail.com)
Date: 05/25/05

  • Next message: hibano haleluya: "Re: Packet/Protocol Anomaly Detection with IDS"
    Date: Wed, 25 May 2005 09:14:30 +0530
    To: Security Focus IDS Forum <focus-ids@securityfocus.com>
    
    

    Hi all,

          I am a new member to this group & i am sure i will get your
    valuable suggestion for my problem.
         I work for an organization where we have almost all the latest
    devices in place, which includes L3 Switches, VOIP,High end server &
    etc. We have around 1500 desktops & this is a production environment.

    My problem

    i) My network manager wants me to suggest an IDS, and i googled
    yesterday i recommened him - Snort.
    ii) I am quite new to IDS and i haven't done even a single
    installation of Snort till now.

    Can anyone let me know the features of Snort, where this sensor should
    be placed in the Network?. Plz dont think that i am not doing my
    homework.i have already started to collect information from Snort.org
    but i find it a little to difficult to undersatnd the concept.

    I need help in how to install Snort?. Finally are there any windows
    edition of Snort avaliable.

    Regards

    Venkatesh

    -- 
    The impossible is often untried.
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: hibano haleluya: "Re: Packet/Protocol Anomaly Detection with IDS"

    Relevant Pages

    • Re: Value of "richer" signatures?
      ... Snort, Dragon, and NFR, and I can tell you that they ... Here's an example of how the newer IDS signatures help ... Let's say you are using a simple packet grepping IDS ... > an FTP connection). ...
      (Focus-IDS)
    • Re: ids inquisition
      ... Subject: ids inquisition ... Snort isn't one of them. ... Brian Caswell - CSV output plugin, ... Christian Lademann - active response, ...
      (Focus-IDS)
    • RE: IDS recommendations
      ... Subject: IDS recommendations ... Snort is a relatively raw tool and that usually adds ... >> I can appreciate your comments on the ISS product. ...
      (Focus-IDS)
    • RE: "Free" IDS
      ... I am very surprised noone mentioned Demarc PureSecure IDS solution. ... It cost less than 2000.00 and it runs off of the snort engine and has a big ... if you want to learn snort then just read up on it. ...
      (Focus-IDS)
    • RE: Test tools for IDS
      ... "Sneeze" is great for Snort IDS. ... Captus Networks IPS 4000 ... Intrusion Prevention and Traffic Shaping Technology to: ...
      (Focus-IDS)