Snort_2
Snort_2
Intrusion Detection
What is Snort
Data
Acquisition Decode Preprocess Detect Action
Design Engine
Packet Sniffer
Packet Logger
NIDS Mode
Inline Mode
Rules
Two Parts
– Rule Header
– Rule Options
Rule Header
IP TTL Content
IP ID Content offset
Fragment size Content depth
TCP Flags Session recording
TCP Ack number ICMP type
TCP Seq number ICMP code
Payload size Alternate log files
Make Custom Rules
Detect String
alert tcp any any -> any any \
(content: clemson; msg: detected clemson!;)
Output
Acid
SnortSnarf
SnortAlert Monitor (SAM)
Snortalog
Guardian
DeMarc PureSecure
IDSCenter (Windoze)
Resources
Snort.org
– www.snort.org/dl (downloads)
BleedingEdge
– www.bleedingsnort.com/
Sourcefire
– www.sourcefire.com