RE: Snort question

From: Chris Wilkes (cwilkes@ladro.com)
Date: 09/27/01


Date: Thu, 27 Sep 2001 09:51:17 -0700 (PDT)
From: Chris Wilkes <cwilkes@ladro.com>
To: Security Basics <SECURITY-BASICS@securityfocus.com>
Subject: RE: Snort question
Message-ID: <Pine.LNX.4.10.10109270949060.12366-100000@cjw.depechecode.com>

On Wed, 26 Sep 2001, Peter Mueller wrote:

> > Question: Would packets that are dropped by the filtering
> > rules reach snort?
> > Please explain your answer. Thank you.
>
> No. Snort functions post-kernel space. On linux the packet filtering
> (ipchains, iptables) is done at the kernel level.

Also (this probably goes without saying) you won't be able to see packets
that are dropped by the NIC; like runts, jumbo packets, etc. Those show
more of a hardware (faulty hub, router, wires, etc) problem and aren't
probably a sign of attack.



Relevant Pages

  • Re: unidentified DOS "bad traffic"
    ... I'd do some closer looking at the source machine. ... Do you have an idea of the volume of packets that were coming from this ... A particular host has been completely flooding the network with ... My Snort output on ...
    (Incidents)
  • Re: unidentified DOS bad traffic
    ... large and/or small packets, and sometimes fragmented. ... flooding most gateways, and connects to an IRC channel as you describe. ... A particular host has been completely flooding the network ... My Snort output on this trace was filled with nothing but ...
    (Incidents)
  • RE: Which intrusion detection to use?
    ... > deny access to all unused ports to the world there will be no ... Snort does not care ... while I would get ipfw dropping packets in my logs, ... If you want a good book I'd recommend "Building Internet Firewalls" by ...
    (FreeBSD-Security)
  • RE: Which intrusion detection to use?
    ... >>> I don't know how tight your particular setup is, but if you deny ... Snort does not care about ... >> and while I would get ipfw dropping packets in my logs, ... > From my experience snort will not catch much in this setup. ...
    (FreeBSD-Security)
  • RE: Any ideas?
    ... this time the first two Packets from Snort show the third part of the TCP ... because the attacker allready knows your server ... These are entries from my Snort IDS logs and my firewall logs for the IP ...
    (Security-Basics)

Quantcast