|
-
July 11th, 2002, 03:55 AM
#10
Junior Member
Answer to the last question first, snort is an IDS = Intrusion
Detection System. Basically a network sniffer that has signatures
of known host and network attacks. These signatures come in the
form of rules or plug-ins each meant to look for the "signature" of
a specific attack.
Original question - definately refer to silicondefense.com (referred to
in one of the above posts) if you will be using windows version.
Just installing snort will not get you all the way to where you want to
be, you need a log analyser/viewer, something to distill and make
sense of all of the alerts. I use snort with snarf to do this. silicon
defense has a great step by step to get this going. There is another
way besides command line to use snort for windows, an application
called IDSCenter - tried it, looks ok, but I prefer the snarf method.
Pretty cool stuff! The maker of snort just went commercial, selling
a preconfigured box with support if you need it.
The step by step is found under the tech support > windows snort
support area of the s.d. website.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|