Kategoriarkiv: Networking

Optimizing snort for high performance / Database

Decouple Snort’s output stage so it can keep pace with the packets. Snort by itself is fine for monitoring small networks or networks with low amounts of traffic, but it does not scale very well without some additional help. The … Læs resten

Udgivet i Knowledge Base, Linux, Networking, Old Base | Skriv en kommentar

Stealthing the sensorts

Keep your IDS sensors safe from attack, while still giving yourself access to their data. Your IDS sensors are the early warning system that can both alert you to an attack and provide needed evidence for investigating a break-in after … Læs resten

Udgivet i Knowledge Base, Linux, Networking, Old Base | Skriv en kommentar

IDS That detect abnormal behaviour automatic

Detect attacks and intrusions by monitoring your network for abnormal traffic, regardless of the actual content. Most NIDS monitor the network for specific signatures of attacks and trigger alerts when one is spotted on the network. Another means of detecting … Læs resten

Udgivet i Knowledge Base, Networking, Old Base | Skriv en kommentar

Dynamic firewall with snortsam

Use SnortSam to prevent intrusions by putting dynamic firewall rules in place to stop in-progress attacks. An alternative to running Snort on your firewall and having it activate filtering rules on the machine it’s running on [Hack #87] is to … Læs resten

Udgivet i Knowledge Base, Linux, Networking, Old Base | Skriv en kommentar

Hack 87 Prevent and Contain Intrusions with Snort_inline

Install Snort_inline on your firewall to contain intrusions, or to stop them as they’re happening. Wouldn’t it be nice if your NIDS could not only detect intrusions, but also do something about them? It would be nice if it could … Læs resten

Udgivet i Knowledge Base, Networking, Old Base | Skriv en kommentar

Writing snort rules

Customize Snort for your own needs quickly and easily by leveraging its flexible rule engine and language. One of the best features of Snort is its rule engine and language. Snort’s rule engine provides an extensive language that enables you … Læs resten

Udgivet i Knowledge Base, Linux, Networking, Old Base | Skriv en kommentar

Snort sencors

Use SnortCenter’s easy-to-use web interface to manage your NIDS sensors. Managing an IDS sensor and keeping track of the alerts it generates can be a daunting task, and even more so when you’re dealing with multiple sensors. One way to … Læs resten

Udgivet i Knowledge Base, Linux, Networking, Old Base | Skriv en kommentar

Realtime monitoring snort , yet another gui

Use Sguil’s advanced GUI to monitor and analyze IDS events in a timely manner. One thing that’s crucial when analyzing your IDS events is to be able to correlate all your audit data from various sources, to determine the exact … Læs resten

Udgivet i Knowledge Base, Networking, Old Base | Skriv en kommentar

Detect intrusions with snort

Use one of the most powerful (and free) network intrusion detection systems available to help you keep an eye on your network. Monitoring your logs can take you only so far in detecting intrusions. If the logs are being generated … Læs resten

Udgivet i Knowledge Base, Networking, Old Base, Security | Skriv en kommentar

Tunnel with PPP and SSH

Use PPP and SSH to create a secure VPN tunnel. There are so many options to choose from when creating a VPN or tunneled connection that it’s mind-boggling. You may not be aware that all the software you need to … Læs resten

Udgivet i Knowledge Base, Networking, Old Base, SSH | Skriv en kommentar