Snort IDS and IPS Toolkit — Featuring Jay Beale and Members of the Snort Team

Data Analysis Tools

Now that we have seen what data analysis consists of, we are going to look at some tools that make our lives easier. We need some support in sifting through thousands of events a day and data analysis tools (when they are good) help a great deal in making sense of the event flood.

Although a plethora of commercial tools is available, we will delve into many of the excellent free tools for applying our intrusion analysis skills. These free but robust tools give everyone the power to analyze data in search of intrusions and misuses.

We are going to start by looking at database front ends. They provide a graphical user interface (GUI) for interacting with the alerts recorded, and they speed up the process of combing through the vast number of alerts. The data processing scripts we introduce after that are very useful for quickly getting an overview of the alerts reported by Snort, or even for finding uncommon or malicious outliers. Visualization tools are even better for gaining an understanding of relationships between alerts and grasping the big picture. They make it easy to spot outliers and isolate them from the rest of the activity. Finally, we will look at real-time alerting tools, which are monitoring the Snort alert log and take specific action based on the alerts observed. Actions can include notifications which are sent off to someone upon detection of a highly severe attack, or a shell script that executes certain commands...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Tank Monitoring Systems
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.