|
|||||||||||
|
RE: dragon and snort logs
From: Golomb, Gary <GGolomb(at)enterasys.com>
Date: Wed May 14 2003 - 11:46:14 EDT
>
Brain is absolutely correct. Many people start using Snort since they first learn how to use IDS though courses like SANS and other introductory courses. Additionally, since Snort is free, it is easy for administrators to use it for initial design and implementation testing. We've seen many people do this while testing solutions from vendors. After the initial stages of an IDS network design, many people upgrade to commercial implementations. When they do, we try our best to support any existing infrastructure they may have. If they have already taken the time to write custom signatures for their existing IDS, we will work with them to import those to Dragon, since Dragon is one of the few commercial solutions to have a fully open signature set - whether the initial implementation was Snort or otherwise. Interestingly enough, we're running into Snort less and less. Now we're needing to convert signatures from the other market leaders since they are starting to open up the ability to write custom detection routines. The tool you reference is one of the tools which Dragon customers have developed for the Dragon community. Being on the Dragonuser mailing list, you should know about how people contribute data mining tools, signatures, and other conversion utilities. If you have missed those, they are freely available on our support site. >
In addition to field support engineers all over the world, you can also utilize our global support call centers, or the rest of the Dragon community on the Dragonuser list. INTRUSION PREVENTION: READY FOR PRIME TIME? IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities - including intrusion identification, relevancy, direction, impact and analysis - enabling a path to prevention. Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: http://www.securityfocus.com/IntruVert-focus-ids2 Received on Wed May 14 12:03:17 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:12 EDT |
||||||||||
|
|||||||||||