Re: Snort IDS

From: Bennett Todd (bet@rahul.net)
Date: 09/24/02


Date: Tue, 24 Sep 2002 16:28:58 -0400
From: Bennett Todd <bet@rahul.net>
To: hejimenez@bancoagricola.com


2002-09-23-18:07:29 hejimenez@bancoagricola.com:
> I'm an EDP auditor and I want to know some commentaries about the
> use of Snort IDS...I'de like to know if anyone recommend it and if
> it's a good choice to install in a financial organization.

I'm a security analyst working in a financial organization.

At this and previous such I've installed Snort IDS sensors.

Snort is among the best of the IDS systems. Different systems have
different strengths, but if the deploying organization has the
expertise to configure and manage snort systems, you can get a very
good coverage that way. Snort sigs are developed and maintained
quite aggressively. The tool itself is sound.

_Any_ IDS deployment requires an appropriate amount of expertise.
Exactly what expertise is required in what fields will vary from one
IDS to another; that's often the most important determinant of which
one is best for a given organization.

You might want to read back issues of the focus-ids mailing list,
also right here at SecurityFocus. Also, there's a very fine
snort-users mailing list with archives reaching back years, it's
linked off www.snort.org.

-Bennett






Relevant Pages

  • Re: Value of "richer" signatures?
    ... Snort, Dragon, and NFR, and I can tell you that they ... Here's an example of how the newer IDS signatures help ... Let's say you are using a simple packet grepping IDS ... > an FTP connection). ...
    (Focus-IDS)
  • Re: ids inquisition
    ... Subject: ids inquisition ... Snort isn't one of them. ... Brian Caswell - CSV output plugin, ... Christian Lademann - active response, ...
    (Focus-IDS)
  • RE: IDS recommendations
    ... Subject: IDS recommendations ... Snort is a relatively raw tool and that usually adds ... >> I can appreciate your comments on the ISS product. ...
    (Focus-IDS)
  • RE: "Free" IDS
    ... I am very surprised noone mentioned Demarc PureSecure IDS solution. ... It cost less than 2000.00 and it runs off of the snort engine and has a big ... if you want to learn snort then just read up on it. ...
    (Focus-IDS)
  • RE: Test tools for IDS
    ... "Sneeze" is great for Snort IDS. ... Captus Networks IPS 4000 ... Intrusion Prevention and Traffic Shaping Technology to: ...
    (Focus-IDS)