Snort Intrusion Detection and Prevention Guide

Answers to frequently asked questions related to the open source Snort intrusion detection and prevention system.

To paraphrase Bruce Schneier, banks do not depend solely on vaults to keep their assets safe; they also employ...

intrusion detection and response mechanisms in the form of alarms and guards. Your network, or more properly the data on it, is one of the most important assets your company has. You already protect it with a vault -- your firewall, and logical and physical network perimeter security. But if you don't have alarms (intrusion detection systems) and guards (incident response), you are not as secure as you could be.

Arguably one of the best network intrusion detection systems (IDS) is the free and open source Snort toolkit. It has a large and active community, and is backed by the commercial company SourceFire, making Snort a strong contender in the intrusion detection systems market. The package itself is free. All that's required is some hardware to run it on and the time to install, configure and maintain it. Snort runs on any modern operating system (including Windows and Linux), but some consider it to be complicated to operate. The goal of this guide is to take some of the mystery out of Snort.

About the author:
JP Vossen, CISSP, is a Senior Security Engineer for Counterpane Internet Security. He is involved with various open source projects including Snort, and has previously worked as an information security consultant and systems engineer.
 
This was last published in May 2005

Dig Deeper on Network Intrusion Detection (IDS)

PRO+

Content

Find more PRO+ content and other member only offers, here.

Join the conversation

1 comment

Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.

I have used Snort for a long time, as well as Snorby as an iFrame. I would recommend Snort but using a different versión of RedBorder, as it is new and improved.
Cancel

-ADS BY GOOGLE

SearchCloudSecurity

SearchNetworking

SearchCIO

SearchConsumerization

SearchEnterpriseDesktop

SearchCloudComputing

ComputerWeekly

Close