|
|||||||||||
|
Re: ISS and Snort logs
From: Brian <bmc(at)snort.org>
Date: Fri Apr 25 2003 - 09:19:49 EDT
On Fri, Apr 18, 2003 at 03:24:58PM -0400, Security Conscious wrote:
A cheaper/uglier option is to have snort log via syslog and use ISS's HIDS component and add signatures in the HIDS for each snort rule you enable. Since you wouldn't be mucking with the underpinnings of ISS's database, you will not get into support/licensing issues. You know the type: "Oh, you did what to the database? OK, first thing. Reinstall." You are running an IDS on NT, so you should be used to this already. ;P Anyway, using the syslog method would This would be easier to setup initially but would require more maintenance as when new rules are added to snort, you will need to add rules to your HIDS. But at least you won't have to pay your DBA more than you already do. That, or you could look at getting an ESM type product that actually handles all of this foo for you. There are dozens of products that attempt to accomplish your specific problem. -brian INTRUSION PREVENTION: READY FOR PRIME TIME? IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities - including intrusion identification, relevancy, direction, impact and analysis - enabling a path to prevention. Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: http://www.securityfocus.com/IntruVert-focus-ids Received on Sat Apr 26 13:40:44 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:11 EDT |
||||||||||
|
|||||||||||