Re: Snortcenter, Prelude-IDS

From: Cedric Foll (cedric.foll_at_ac-rouen.fr)
Date: 08/16/05

  • Next message: David J. Bianco: "Re: IDS - DECISION SUPPORT SYSTEM"
    Date: Tue, 16 Aug 2005 10:23:16 +0200
    To: Sven Müller <smueller@magellan-net.de>
    
    

    Hi,

    >
    > Do you have any experiences with Prelude?
    >

    I use it for several months and i'm really happy with it.

    If you want only use snort (it's what i do) this is the idea:
    You install several snort v2.4.0. This version is able to send repport
    to a prelude manager.
    Then you install a prelude-manager and configure all your snort to
    repport their alert their. It's very easy and secure (ssl protocol with
    host and server auth via a pre-shared key).
    So you centralize all your alert and you can visualize them via prewikka
    a very nice web-based application.

    Furthemore, the ml is very responsive, the team is helpful and kind.

    Regards.

    -- 
    Cedric Foll
    Ingénieur Sécurité & Réseaux
    Division Informatique, Rectorat de Rouen
    "More people are killed every year by pigs than by sharks,
    which shows you how good we are at evaluating risk."
    Bruce Schneier
    ------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it 
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    ------------------------------------------------------------------------
    

  • Next message: David J. Bianco: "Re: IDS - DECISION SUPPORT SYSTEM"

    Relevant Pages

    • Re: Are there any other open sources IDS that not based on snort?
      ... Prelude is not based on the snort architecture, ... I am doing a research on network security concentrating on correlation ...
      (Focus-IDS)
    • ANNOUNCE: Prelude Reporting Patch for Snort
      ... Prelude Reporting Patch for Snort 1.8.7 and 1.8.6 ... The Prelude Development Team is proud ... sending alerts in the common format using the libprelude library. ...
      (Focus-IDS)
    • Re: Mandrake MNF
      ... switching on the Snort or Prelude, hung on boot, only way out was reinstall. ... > Mandrake has released the next version of their Single Network Firewall. ...
      (comp.security.firewalls)
    • Re: IDS Opinions
      ... Prelude markets themselves as a framework, ... does quite a bit more than Snort. ... snort-a-like implementations, or they provide their own "complete" ...
      (Focus-IDS)
    • [UNIX] Buffer Overflow in Snort RPC Preprocessor
      ... A buffer overflow has been found in the Snort RPC normalization routines ... The first option will alert on any RPC fragmented record it finds. ... current packet length. ...
      (Securiteam)