Snort IDS and IPS Toolkit — Featuring Jay Beale and Members of the Snort Team

Chapter 10: Optimizing Snort

Introduction

So Snort is wonderful and everyone understands how you install and configure it to find all the intrusions and "bad guys" on the network and everyone is happy. But there's still one essential question you must know the answer to: Can you make sure there's no packet loss, and be certain your system is beefy enough to handle every task? If Snort isn't installed on the appropriate machine, it will strongly affect the results and overall usage of the application. Unlike other appUcations that mainly rely on memory and CPU power. Snort depends on several aspects of the operating system, including network cards, memory, hard disk write speed, hard disk space, and processing power. This chapter explains several system configurations that will attempt to optimize Snort performance for different business requirements on diverse network environments.

In the chapter's first few sections, we examine the hardware necessary to run Snort on several OS platforms and network configurations. As might be expected, given such vastly different OSs (Linux, BSD, Windows, or Solaris), the amount of computing power required to run Snort efficiently varies wildly. An important note to keep in mind is that the goal of building a Snort box is to limit any type of packet loss. Otherwise, you could miss an attack or fail to log a crucial bit of evidence.

Later in the chapter, we discuss the pros and cons of the various OSs for running Snort. The choice of using Linux, BSD, Windows, or Solaris depends mostly...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: RFID Software
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.