Home > Top five Snort tips
Top Tips:
EMAIL THIS

Top five Snort tips

02 Nov 2007 | SearchSecurityChannel.com

Security Channel Update
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Our Snort Report tip series helps value-added resellers and systems integrators troubleshoot and configure the open source intrusion detection system on clients' networks. Check out our five most popular tips from expert Richard Bejtlich, ranging from setting up the IDS to upgrading it.

TIP #1-----------------------------------------------------------------------

Snort IDS installation basics and tips for security resellers
Snort can be immensely helpful with the prevention of intrusions on your clients' networks. Learn how to install the intrusion detection system and utilize it to its fullest capacity.

TIP #2-----------------------------------------------------------------------

Snort IDS upgrade and tips on the Snort.conf file
Check out this tip for details on the Snort 2.6.1.2 upgrade and snort.conf file functions enabled by default, such as IP ranges, ports of interest and preprocessors.

TIP #3-----------------------------------------------------------------------

Snort Report
Read the rest of the Snort Report tips from Richard Bejtlich

Output options for Snort data
Without output options, VARs can't produce Snort data in a meaningful manner. Learn the capabilities and limitations of different features.

TIP #4-----------------------------------------------------------------------

How to test Snort
As a value-added reseller or service provider, you may need to test Snort to ensure that the open source IDS is detecting malicious activity on your client's network or to determine how the custom rule you wrote will impact Snort's performance. Learn the best practices for testing Snort.

TIP #5-----------------------------------------------------------------------

Snort IDS rules
Familiarize yourself with Snort IDS rules best practices in this edition of Snort Report, which includes a discussion on Sourcefire and Bleeding Edge Threats (BET) rules.



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Network intrusion detection and prevention defenses
SIEM services help customers with security monitoring
Implementing IDS/IPS technologies: Managing politics and accountability
Juniper launches mid-level security appliances
Must-haves for wireless network security: WLAN switches, intrusion detection and more
Host-based IDS/IPS Partner Program Directory
Understanding Snort's Unified2 output
Network security algorithms introduction
Searching for multiple strings in packet payloads
Approximate string matching
Detecting worms

Snort Report
Snort vs. Microsoft Security Bulletin MS08-068
Understanding Snort's Unified2 output
Using Snort 2.8.3 to inspect HTTP traffic
Using SnortSP and Snort 2.8.2
The power of Snort 3.0
How to find new features in Snort 2.8.2
Top security tips for solutions providers
When Snort is not enough
Justifying Snort
Network session data analysis with Snort and Argus

Snort
The power of Snort 3.0
When Snort is not enough
Justifying Snort
Network session data analysis with Snort and Argus
How to use shared object rules in Snort
Why is the Snort IDS still alive and thriving?
How can the operator test Snort?
How can I learn more about Snort?
Snort limitations
Snort 2.8.0 new features: IPv6 and port lists

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts