Snort 2.0 Intrusion Detection

Chapter 2: Introducing Snort 2.0

Introduction

You probably picked up this book because you've heard of Snort as an open-source network security solution. However, Snort is more than that. Snort is a full-fledged, open-source, Network-based Intrusion Detection System (NIDS) that has many capabilities. These capabilities include packet sniffing and packet logging in addition to intrusion detection. In addition to all of the basic Snort Features, you can set up Snort to send real-time alerts. This provides you with the ability to receive alerts in real time, rather than having to continuously monitor your Snort system.

Snort is like a vacuum that takes particular items (in this case, packets) and allows you to do different things. You can either watch the items as they get sucked up (packet sniffer), put the items into a container (packet logger), or it can sort them and let you know when a particular item has gone through your NIDS.

So why is Snort so popular? Providing packet sniffing and logging functions is an elementary part of Snort, but Snort's beefiness comes from its intrusion detection capabilities which matches packet contents to an intrusion rule. Snort might be considered a lightweight NIDS. A "lightweight" intrusion detection system (IDS) is one that has a small footprint and can run on various operating systems (OSs). Additionally, Snort provides functionality only before found in commercial-grade network IDSs such as Network Flight Recorder (NFR) and ISS RealSecure.

Snort's popularity runs parallel to the increasing popularity of Linux and other free OSs such as the BSD-based OSs...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Network Firewalls
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.