Snort IDS and IPS Toolkit: Featuring Jay Beale and Members of the Snort Team

Frequently Asked Questions

The following Frequently Asked Questions, answered by the authors of this book, are designed to both measure your understanding of the concepts presented in this chapter and to assist you with real-life implementation of these concepts. To have your questions about this chapter answered by the author, browse to www.syngress.com/solutions and click on the "Ask the Author" form.

Q:

What database permissions are needed for proper BASE functioning?

Q:

How can I add support for portscan file processing by BASE?

Q:

When I start my Swatch script in the background And, it stops soon afterward. What's wrong?

Q:

Is it possible to browse the contents of a packet that triggered an alert in SnortSnarf?

Q:

Q: Can I run SGUIL as a pull architecture IDS?

Q:

What incident categories are built into SGUIL?

Q:

Is it possible to monitor network traffic in real time with AfterGlow?

Answers

Q:

Snort needs only Insert and Select privileges to log on to a database. BASE needs Select privileges for running queries, Insert and Update for alert group support and caching, and Delete for alert deletion.

Q:

It is a little tricky. When logging to a database. Snort only logs an occurrence of the portscan event and not all of the port's data. It is possible to force BASE to process a text portscan log (only one file can be configured). The file to be processed is configured in the $portscan_file variable. BASE...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: I/Q Modulators and I/Q Demodulators
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.