Index
259
set_gid directive, 114
sample, 118 119
set_uid directive, 115
using variables in rules, 112 113
sid
keyword, 110
daemon, 29
Signature based intrusion detection systems,
downloading, 28
5
FAQ, 20, 21, 29
file locations, 56 57
Signatures, 5, 7, 75
attack, 11
getting started with, 23 73
defined, 7
installing, 24 53
updating, 11
multiple Snort sensors with central
ized database, 26 28
Simple Network Management Protocol
from RPM package, 28 29
(SNMP), 3
single sensor production IDS, 24 25
Simple Network Modeling Language
single sensor with database and Web
(SNML), 146, 156
interface, 25 26
SLIP, 13
single sensor with network manage
SMB alerts, 28
ment system integration, 25
SMB alerts module, 139
from source code, 29 42
SMTP header, 14
test installation, 24
SNML DTD, 245 250
modes, 58 66
SNMP header, 15
alert modes, 66 71
network intrusion detection mode,
SNMP information, web site, 73
65 66
SNMP, sending alerts to, 69
network sniffer mode, 58 65
SNMP traps, 16, 23, 83
with no IP address interface, 20 21
output module, 154
and preprocessor/output modules, 131
SNMPv2 trap, general format of, 154
protocols understood by, 83 84
Snoop, 58
restarting, 29
Snort, 2, 7, 21
rule actions, 81 83
binary files, 56
activate action, 82
command line options, 55 56
alert action, 82
components of, 12 16
dynamic action, 82
detection engine, 14 16, 155
log action, 82
logging and alerting system, 15
pass action, 82
output modules, 15 16
user defined actions, 82 83
packet decoder, 13
rule headers, 81 83
preprocessors, 13 14
rule options, 88 111
configuration file, 112 119
ack
keyword, 89
config directives, 114 15
classtype
keyword, 89 93
defining new action types, 117
content
keyword, 93 94
include files, 117 118
content list
keyword, 95
output module configuration, 116
depth
keyword, 95
117
dsize
keyword, 95 96
preprocessor configuration, 116
flags
keyword, 96 97
rules configuration, 117
flow
keyword, 108 109
footer
Our partners:
PHP: Hypertext Preprocessor Cheap Web Hosting
JSP Web Hosting
Ontario Web Hosting
Jsp Web Hosting
Cheapest Web Hosting
Java Hosting
Cheapest Hosting
Visionwebhosting.net Business web hosting division of Vision Web Hosting Inc.. All rights reserved