Snort 2.0 Intrusion Detection

Chapter 9: Keeping Everything Up to Date

Introduction

As with many other open-source projects, the Snort Intrusion Detection System (IDS) is evolving all the time. To keep up with its development and use additional features that appear in new releases, you need to be able to update your installation periodically. The update process is usually simple versions of Snort are backward compatible so all you need to do is recompile the source (if you prefer building Snort yourself) or reinstall a package; for example, a Red Hat .RPM module, which is available from the distribution site.

As with all open-source projects, it is possible that someone has coded some extra functionality into his Snort package that is not in the distributed version, and you want to try it out. In this case, you can patch your Snort source code with the changes distributed by that person and see the results.

The most important updates are the rule updates that should be applied to the Snort sensors. Rule updates are created by other people in response to emergencies, such as new, overwhelming attacks similar to CodeRed and the recent MS SQL Slammer worms. Several rule databases are updated on a regular basis and available at various Web sites; for example, www.snort.org and www.whitehats.com If you plan to stay current with new attack detection (and you probably will), you need to continuously monitor one or more sources for new rules and regularly update your rule files. Several tools exist for performing this task, and this chapter describes their uses.

Applying Patches

If...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Direct Mail and Fulfillment Services
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.