Network Intrusion Analysis by Joe Fichera & Steven Bolt

Network Intrusion Analysis by Joe Fichera & Steven Bolt

Author:Joe Fichera & Steven Bolt
Language: eng
Format: epub
ISBN: 9781597499712
Publisher: Elsevier Inc.
Published: 2012-10-23T16:00:00+00:00


Snort

One suggestion I have is to use another open source tool, Snort. Snort is a network intrusion prevention and detection system (IPS/IDS) that was developed by Sourcefire. Snort[5] can be downloaded from <http://www.snort.org>. In addition to downloading the Snort installer, you will also have to download the Snort rules. To download the rules, you will have to register for an account. If you are going to be running snort on a Windows box, as I am, you will need to do some editing of the snort.conf file. It is pretty straight forward and self-explanatory. One of the settings I always like to add is the CSV out put option. I do this so that once I run a capture file through Snort, I end up with a .csv log that I can then open in Excel and easily sort.

To add the CSV output, add the following line in the output plugin section of the snort.conf file (see Figure 5.1).



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.