The Best Damn Firewall Book Period

Part VI: Intrusion Detection

Chapter List

Chapter 29: Introducing Snort
Chapter 30: Installing Snort
Chapter 31: Combining Firewalls and IDS

Introduction

Snort is a full-fledged open-source Network-based Intrusion Detection System (NIDS) that has many capabilities. These capabilities include packet sniffing and packet logging in addition to intrusion detection. In addition to all of the basic Snort Features, you can set up Snort to send real-time alerts. This provides you with the ability to receive alerts in real time, rather than having to continuously monitor your Snort system.

An Intrusion Detection System (IDS) is used as a "burglar alarm" for your network or host. If there is an anomaly detected (in the case of Snort, by using signatures), the system administrator is notified in various ways. Those ways include e-mail, network messages (like Windows pop-ups or UNIX write), or the syslog facility.

Snort is like a vacuum that takes particular items (in this case, packets) and allows you to perform different tasks, such as watching the items as they get sucked up (packet sniffer), putting the items into a container (packet logger), or sorting them and determining when a particular item has gone through your NIDS.

So why is Snort so popular? Providing packet sniffing and logging functions is an elementary part of Snort, but Snort's beefiness comes from its intrusion detection capabilities which matches packet contents to an intrusion rule. Snort might be considered a lightweight NIDS. A lightweight IDS is one that has a small footprint and can run on various operating systems...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Network Firewalls
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.