Snort IDS and IPS Toolkit — Featuring Jay Beale and Members of the Snort Team

Chapter 9: Exploring IDS Event Analysis, Snort Style

Introduction

Snort, at its heart, is a very complex pattern matcher geared toward detecting pat- terns of network traffic. On any given network, on any given day, Snort can fire thousands of alerts (and that's on a small network). Your task as an intrusion analyst is to sift through the data, extract events of interest, and separate the false positives from the actual attacks.

In this chapter, we will cover the methodology and tools for managing the task of monitoring Snort sensors and analyzing intrusion data. The tools we will cover are:

  • BASE

  • SGUIL

  • Snort_stat.pl

  • SnortSnarf

  • SnortALog

  • EtherApe

  • Shoki-Packet Hustler

  • AfterGlow

  • Swatch

  • Tenshi

  • Pig Sentry

  • openSIMs

  • OSSIM

For your convenience, the current versions of these tools (at the time of this writing) are included on this book's companion CD-ROM. You can find these tools in the Chapter 9 directory.

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Network Firewalls
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.