Snort 2.0 Intrusion Detection

Chapter 5: Playing by the Rules

Introduction

It might come as a surprise to you, but intrusion detection systems (IDSs) are not a bleeding-edge technology, and Snort is no exception. In fact, Snort is the one of the oldest IDSs that is still supported. So, why are you reading this book? We are about to tell you. Snort is the most popular and widely used packet sniffer and intrusion detection engine in the world. Its rules-based engine (notice that we did not say signature-based engine) collects and correlates packets based on rules. The term signature refers to nothing more than a basic definition of an attack, akin to the footprint left in the mud by the shoe of someone breaking into a house. A rule defines the attack methodology in terms of identifying the intruder, analogous to identifying how the robber broke into the house in hopes of catching the robber.

When technologists discuss IDSs, Snort always stands apart from the crowd because of two key differentiators: flexibility and simplicity. These features were two of the initial design goals during the development of Snort and carried through during the design of the rule schema and engine support modules of the application. Many Snort rules can be written in one line of text, and before version 1.8, it was mandatory that rules be only one line. A tremendous number of Snort users do not use Snort to its fullest potential. Throughout this chapter, you will learn the importance of proper rule creation and how you could...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Network Firewalls
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.