Language Selection

English French German Italian Portuguese Spanish

When Snort is not enough

Filed under
Software

As an independent security consultant I offered a course to customers called Network Security Operations, which covered network-centric intrusion detection, response and forensics. Students often asked, "Is this the Snort course?" And I answered, "Not exactly, but you're probably in the right place."

I've been inspecting and acting upon network traffic for 10 years. When I tell people that I use network traffic as one means to detect and respond to intrusions, many respond by saying, "So you use Ethereal, right?" I find myself responding in a similar manner to the Snort question: "Not exactly, but sometimes."

Both of these questions point to customer perceptions of common ways to detect and respond to intrusions. The digital security field is incredibly complicated and anyone who claims to be a master of the entire field is a fool. In fact, mastery of any single subject might require such narrow focus as to be of little relevance to the remainder of the field. Those who are most successful have carved some niche out of the security landscape, but still understand the rest of the arena.

More Here




re: Snort

Snort is IDS (not IPS), and generates WAAAAAAAAAAY more false alarms then any real attacks.

The author states: "At the end of the day, you can never have enough data." - I guess that's true when you're a "security consultant" and charge by the hour to wade thru the reams of fluff looking for a line or two indicating a real attack (like SETI only not as exciting - or probable).

Firewalls are like windshields - they both catch a zillon nasties ON THE OUTSIDE. It's only when they come INSIDE do you have to worry.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

More in Tux Machines

4MLinux 17.0 OS Hits the Stable Channel, Brings Firefox 46.0 & Thunderbird 45.0

Softpedia has been informed by 4MLinux developer Zbigniew Konojacki about the general availability of his 4MLinux 17.0 independent, desktop-oriented GNU/Linux distribution. Read more

Linux 4.6-rc6

Things continue to be fairly calm, although I'm pretty sure I'll still do an rc7 in this series. There's nothing particularly scary in here - there's a fix for a long-standing infiniband interface problem, but since you actually have to have the hardware for that, it's not like that is going to affect all that many people, and the workaround was pretty straightforward. The bulk of the rest is really just the normal random noise. Drivers (sound, gpu, ethernet being the bulk of it), architectures (arm, s390, x86), networking is the bulk of it. Shortlog appended for your edification, Linus Read more Also: Linux 4.6-rc6 Kernel Released, Codenamed "Charred Weasel"

DragonBox Pyra

  • DragonBox Pyra Goes Up For Pre-Order
    It's been a while since last hearing anything about the DragonBox Pyra as an open-source gaming handheld system and successor to OpenPandora...
  • Bitcoin is Now Accepted For DragonBox Pyra Pre-orders
    It is always good to see new merchants accepting Bitcoin payments, as it goes to show businesses want to attract an international clientele. DragonBox, a ship based in Germany, recently started accepting Bitcoin payments for their Pyra computer. A neat little device, which packs quite the punch.
  • DragonBox Pyra pre-orders begin (open Source handheld gaming PC)
    The DragonBox Pyra is a portable computer that looks like a cross between a tiny laptop and a Nintendo DX game console… and it kind of works like a cross between those devices as well. It’s got a 5 inch display, a QWERTY keyboard, the Debian Linux operating system that can handle desktop apps as well as games, and physical gaming buttons.

DragonBox Pyra pre-orders begin (open Source handheld gaming PC)

The DragonBox Pyra is a portable computer that looks like a cross between a tiny laptop and a Nintendo DX game console… and it kind of works like a cross between those devices as well. It’s got a 5 inch display, a QWERTY keyboard, the Debian Linux operating system that can handle desktop apps as well as games, and physical gaming buttons. It’s been under development for several years, and it’s expected to be available for purchase soon for about 500 Euros (plus VAT). But if you want to help fund the developers you can now place a pre-order for 330 Euros and up. Read more