Re: IDS for Unix

From: Stef (stefmit_at_gmail.com)
Date: 06/30/05

  • Next message: Seek Knowledge: "ATM decoding"
    Date: Wed, 29 Jun 2005 22:52:49 -0500
    To: focus-ids@securityfocus.com
    
    

    1. The Snort rules are the same for Windows, as they for UNIX, so the
    GUI is not helpful there. You are confusing the GUI access to
    configuration, with rules ... and configuration is simple, anyway.
    2. There is nothing easier to learn (and to understand) than what you
    have access to the source of (hint, hint) ...
    3. If you plan to run an IDS with
    "point-and-click-drag-and-drop-I-do-not-know-what-the-hell-is-behind-it",
    then I'd rather suggest you looking into other areas of this
    ever-expanding wonderful world of computing ...

    Stef

    On 6/29/05, Baron Biza <baron.biza@gmail.com> wrote:
    > Hello, Im new in this list, I never used IDS, I want start with one
    > for Unix (FreeBSD and Linux also), I know about Snort but there are a
    > lot of rules to configure by hand,, the WIndows users of Snort have a
    > program in graphic mode to configure their Snort, but we not :-(, is
    > there any IDS good,with the same level,in graphic mode,or easiest to
    > learn?,thnx,good luck.

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Seek Knowledge: "ATM decoding"

    Relevant Pages

    • Re: Value of "richer" signatures?
      ... Snort, Dragon, and NFR, and I can tell you that they ... Here's an example of how the newer IDS signatures help ... Let's say you are using a simple packet grepping IDS ... > an FTP connection). ...
      (Focus-IDS)
    • Re: ids inquisition
      ... Subject: ids inquisition ... Snort isn't one of them. ... Brian Caswell - CSV output plugin, ... Christian Lademann - active response, ...
      (Focus-IDS)
    • RE: IDS recommendations
      ... Subject: IDS recommendations ... Snort is a relatively raw tool and that usually adds ... >> I can appreciate your comments on the ISS product. ...
      (Focus-IDS)
    • RE: "Free" IDS
      ... I am very surprised noone mentioned Demarc PureSecure IDS solution. ... It cost less than 2000.00 and it runs off of the snort engine and has a big ... if you want to learn snort then just read up on it. ...
      (Focus-IDS)
    • RE: Test tools for IDS
      ... "Sneeze" is great for Snort IDS. ... Captus Networks IPS 4000 ... Intrusion Prevention and Traffic Shaping Technology to: ...
      (Focus-IDS)