Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: ISS and Snort logs

From: Brian <bmc(at)snort.org>
Date: Fri Apr 25 2003 - 09:19:49 EDT

On Fri, Apr 18, 2003 at 03:24:58PM -0400, Security Conscious wrote:
> Another option would be to use Snorts SQL Server output module and sends

A cheaper/uglier option is to have snort log via syslog and use ISS's HIDS component and add signatures in the HIDS for each snort rule you enable. Since you wouldn't be mucking with the underpinnings of ISS's database, you will not get into support/licensing issues. You know the type:

   "Oh, you did what to the database? OK, first thing. Reinstall."

You are running an IDS on NT, so you should be used to this already. ;P

Anyway, using the syslog method would This would be easier to setup initially but would require more maintenance as when new rules are added to snort, you will need to add rules to your HIDS. But at least you won't have to pay your DBA more than you already do.

That, or you could look at getting an ESM type product that actually handles all of this foo for you. There are dozens of products that attempt to accomplish your specific problem.

-brian



INTRUSION PREVENTION: READY FOR PRIME TIME?   IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities - including intrusion identification, relevancy, direction, impact and analysis - enabling a path to prevention.  
Do you need help?X

Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: http://www.securityfocus.com/IntruVert-focus-ids Received on Sat Apr 26 13:40:44 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:11 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library