Snort Intrusion Detection and Prevention Guide |
 |
| 05 May 2005 | SearchSecurity.com |
 |


|
by JP Vossen
To paraphrase Bruce Schneier, banks do not depend solely on vaults to keep
their assets safe; they also employ intrusion detection and response mechanisms in
the form of alarms and guards. Your network, or more properly the data on
it, is one of the most important assets your company has. You already
protect it with a vault -- your firewall, and logical and physical network perimeter
security. But if you don't have alarms (intrusion detection systems) and guards (incident response), you are not as secure as you could
be.
Arguably one of the best network intrusion detection systems (IDS) is the free and open source Snort toolkit. It has a large and
active community, and is backed by the comme...
To continue reading for free, register below or login
To read more you must become a member of SearchSecurity.com
 |
|
BROWSE BY TAG
Network Intrusion Detection (IDS),
Network Intrusion Detection and Analysis,
Enterprise Network Security,
Network Intrusion Prevention (IPS),
Monitoring Network Traffic and Network Forensics,
Network Security: Tools, Products, Software,
Network Device Management,
Application and Platform Security,
Open Source Security Tools and Applications, VIEW ALL TAGS
|
 |
');
// -->

rcial company SourceFire, making Snort a
strong contender in the intrusion detection systems market. The package itself is free. All
that's required is some hardware to run it on and the time to install,
configure and maintain it. Snort runs on any modern operating system
(including Windows and Linux), but some consider it to be complicated to
operate. The goal of this guide is to take some of the mystery out of
Snort.
ABOUT THE AUTHOR:
[IMAGE]JP Vossen, CISSP, is a Senior Security Engineer for Counterpane Internet Security. He is involved with various open source
projects including Snort, and has previously worked as an information security consultant and systems engineer.

|
 |
|
 |