Snort IDS and IPS Toolkit — Featuring Jay Beale and Members of the Snort Team

Snort, at its heart, is a very complex pattern matcher geared toward detecting pat- terns of network traffic. On any given network, on any given day, Snort can fire thousands of alerts (and that's on a small network). Your task as an intrusion analyst is to sift through the data, extract events of interest, and separate the false positives from the actual attacks.
In this chapter, we will cover the methodology and tools for managing the task of monitoring Snort sensors and analyzing intrusion data. The tools we will cover are:
BASE
SGUIL
Snort_stat.pl
SnortSnarf
SnortALog
EtherApe
Shoki-Packet Hustler
AfterGlow
Swatch
Tenshi
Pig Sentry
openSIMs
OSSIM
For your convenience, the current versions of these tools (at the time of this writing) are included on this book's companion CD-ROM. You can find these tools in the Chapter 9 directory.