viii
Contents
Chapter 2
Installing Snort and Getting Started
23
2.1 Snort Installation Scenarios
24
2.1.1
Test Installation
24
2.1.2
Single Sensor Production IDS
24
2.1.3
Single Sensor with Network Management System Integration
25
2.1.4
Single Sensor with Database and Web Interface
25
2.1.5
Multiple Snort Sensors with Centralized Database
26
2.2 Installing Snort
28
2.2.1
Installing Snort from the RPM Package
28
2.2.2
Installing Snort from Source Code
29
2.2.3
Errors While Starting Snort
43
2.2.4
Testing Snort
43
2.2.5
Running Snort on a Non Default Interface 51
2.2.6
Automatic Startup and Shutdown 52
2.3 Running Snort on Multiple Network Interfaces
54
2.4 Snort Command Line Options
55
2.5 Step By Step Procedure to Compile and Install Snort
From Source Code
56
2.6 Location of Snort Files
56
2.7 Snort Modes
58
2.7.1
Network Sniffer Mode
58
2.7.2
Network Intrusion Detection Mode
65
2.8 Snort Alert Modes
66
2.8.1
Fast Mode
67
2.8.2
Full Mode
68
2.8.3
UNIX Socket Mode
68
2.8.4
No Alert Mode
69
2.8.5
Sending Alerts to Syslog
69
2.8.6
Sending Alerts to SNMP
69
2.8.7
Sending Alerts to Windows
70
2.9 Running Snort in Stealth Mode 71
2.10 References 73
Chapter 3
Working with Snort Rules
75
3.1 TCP/IP Network Layers
76
3.2 The First Bad Rule
77
3.3 CIDR 78
3.4 Structure of a Rule
79
footer
Our partners:
PHP: Hypertext Preprocessor Cheap Web Hosting
JSP Web Hosting
Ontario Web Hosting
Jsp Web Hosting
Cheapest Web Hosting
Java Hosting
Cheapest Hosting
Visionwebhosting.net Business web hosting division of Vision Web Hosting Inc.. All rights reserved