Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - snort

 
Thread Tools Search this Thread
Old 01-07-2004, 02:39 PM   #1
Default snort


Is it worth paying $10,000 for source fire to make using SNORT easier?
Does using source fire with SNORT make SNORT a middle weight IDS solution as
opposed to a lightweight?

http://www.insecure.org/tools2000.html

_Or_ is it worth the time and energy to write your own scripts and updates.







Dan
  Reply With Quote
Old 01-08-2004, 12:58 AM   #2
Hairy One Kenobi
 
Posts: n/a
Default Re: snort
"Dan" <> wrote in message
news:Zb-dnVqkX42Kh2GiRVn-...
> Is it worth paying $10,000 for source fire to make using SNORT easier?
> Does using source fire with SNORT make SNORT a middle weight IDS solution

as
> opposed to a lightweight?
>
> http://www.insecure.org/tools2000.html
>
> _Or_ is it worth the time and energy to write your own scripts and

updates.

IMHO. Let's say that again: "IMHO"

Any IDS tool (or something that acts as an IDS tool) is only useful if
someone can act on the results.

Not sure where $10k came from..? It's an interesting interface to LibPCap,
isn't it? Just like Ethereal? Are you looking at buying-in a monitoring
service, or deploying something yourself? Did I miss something about
Commercial licensing?

Please point out where the shoe's going to drop.. ;o)

H1K




Hairy One Kenobi
  Reply With Quote
Old 01-08-2004, 01:57 AM   #3
Alexander Delarge
 
Posts: n/a
Default Re: snort

"Dan" <> wrote in message
news:Zb-dnVqkX42Kh2GiRVn-...
> Is it worth paying $10,000 for source fire to make using SNORT easier?
> Does using source fire with SNORT make SNORT a middle weight IDS solution

as
> opposed to a lightweight?
>
> http://www.insecure.org/tools2000.html
>
> _Or_ is it worth the time and energy to write your own scripts and

updates.

No! A friend of mine bought sourcefire box for their school. The thing was a
waste of money. They had to send it back at least two times for repairs. It
never worked properly.

If you're going to use Snort, just save your money and build your own
system. Or use a different IDS entirely.

Alex




Alexander Delarge
  Reply With Quote
Old 01-08-2004, 02:18 AM   #4
Stephen K. Gielda
 
Posts: n/a
Default Re: snort
In article <Zb-dnVqkX42Kh2GiRVn->, bitsandbytes88
@hotmail.com says...
> Is it worth paying $10,000 for source fire to make using SNORT easier?
> Does using source fire with SNORT make SNORT a middle weight IDS solution as
> opposed to a lightweight?
>
> http://www.insecure.org/tools2000.html
>
> _Or_ is it worth the time and energy to write your own scripts and updates.
>


Setup snort to log to mysql then front end it with acid. If you need
help with the setup, there are half a dozen open source front ends to
help. If you are willing to put in the config time, you can build a
very nice solution from snort with remote probes at all ingress and
egress points centrally logging with a nice web interface for anlyzation
of results all from freely available software. I've done such for a
number of larger companies with excellent results. Spend the money on
hardware.

/steve
--
You simply cannot get more server side control of
your e-mail without running your own mail server and
knowing how to program.
http://www.cotse.net/privacyservice.html


Stephen K. Gielda
  Reply With Quote
Old 01-08-2004, 03:00 AM   #5
John
 
Posts: n/a
Default Re: snort
On Wed, 07 Jan 2004 09:39:19 -0500, Dan wrote:

> Is it worth paying $10,000 for source fire to make using SNORT easier?
> Does using source fire with SNORT make SNORT a middle weight IDS solution as
> opposed to a lightweight?
>
> http://www.insecure.org/tools2000.html
>
> _Or_ is it worth the time and energy to write your own scripts and updates.



You may be confused about "lightweight IDS". The term refers to the
adaptability/flexibility of the program, not its capability.

In other words, snort runs on multiple platforms, is relatively easy to
setup and doesn't require lots of power from the host system.

Can't speak for the price you quote but Sourcefire sells hardware
solutions using snort plus technical support. You can roll your own rather
easily if you have someone available with good network/security skills.
Updated signatures are available from a variety of sources, you can also
create or modify existing signatures unlike many proprietery IDS systems.


John
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46