Home > Ask the Security Experts > Questions & Answers > Is Snort better than proprietary IDS?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Is Snort better than proprietary IDS?

JP Vossen EXPERT RESPONSE FROM: JP Vossen

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site
>
QUESTION POSED ON: 21 January 2004
How is Snort (open source) "better" than proprietary software? Is Snort difficult to manage or to find support for?

>
EXPERT RESPONSE

I would argue that Snort is better than a proprietary solution because it is open source. See http://www.dwheeler.com/oss_fs_why.html and http://www.opensource.org/ for the general arguments, but I'll address some specifics here.

First, open source has the potential for more peer review, which translates into quality assurance. No software is bug free, but no company can afford to hire the number of people worldwide who take an interest in reviewing and securing open source code. Be aware that just because the potential exists does not mean that all open source code is extensively reviewed, but given Snort's popularity it's safe to say that a lot of people have looked at the code.

Second, and more important in this case, Snort's rules are open source also. The rules or signatures are the heart of a signature-based IDS. They describe the malicious traffic patterns to look for and alert on if found. The problem with many of the commercial products is that you don't get to see the actual rule. All you get to see is a couple of paragraphs that someone at the vendor wrote about what that rule is SUPPOSED to do. Some vendor descriptions are better than others, but the bottom line with Snort is that I can see the actual code that triggered the alert. That means that I get to evaluate how relevant I find the alert, and I don't have to depend on the person at the vendor who wrote the paragraph. When you spend a lot of time looking at IDS events, which I do, this is key.

Snort is no more difficult to manage than any other IDS. The biggest challenge is probably picking which tools and operating system you want, since Snort runs on Windows and all major UNIX variations. Several companies support Snort appliances with Web GUI management and reporting tools. If you work in an environment where it's easier to get a product by paying for it than by downloading it for free, definitely check out SourceFire, the actual creators of Snort. There are other options as well. Google is your friend.

Finally, you will receive free support from the Snort user community. Check the Snort.org Web site for the FAQ and mailing lists.


For more info on this topic, please visit these SearchSecurity.com resources:
  • Best Web Links: Open source security
  • Network Security Tip: Snort -- The poor man's intrusion-detection system
  • Guest Commentary: IDS and IPS in 2004


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts