Tuning Snort and flex response

11/12/08 | by Andrew Useckas [mail] | Categories: Uncategorized

Tuning Snort

Snort can be a very useful tool in any network environment. However it's not enough to just install it and monitor the events. After Snort is installed and operational you will no doubt notice a lot of so called "false positives" - Snort alerts that are set off by a legitimate traffic. You will also notice legitimate events that repeat over and over again, filling up the logs. Example of such event could be FTP brute force attack, when a malicious user is running brute forcing tools such as "hydra" to try and guess FTP accounts and passwords.

With all of this in mind, it is important to tune the Snort installation in order to reduce the noise, or "false positive" to legitimate alert ratio. Here are some steps that you can follow to accomplish the task.

Read more »

Installing Snort sensor with Mysql and BASE on CentOS Linux

10/30/08 | by Andrew Useckas [mail] | Categories: Uncategorized

Why Centos?

CentOS is an Enterprise-class Linux Distribution derived from sources freely provided to the public by Redhat. It is basically a free version of Redhat's Enterprise Linux Server, so it's a good choice for stable, easy to install Linux server. Making it a perfect choice for a Snort sensor.

Read more »

Pages: 1 · 2 · 3

July 2010
Sun Mon Tue Wed Thu Fri Sat
 << <   > >>
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Andrew Useckas shares his Linux experience

Search

XML Feeds

powered by b2evolution free blog software