Snort mailing list archives
Bleeding Snort rules and Sourcefire Official rules
From: hchlai () netscape net
Date: Tue, 25 Oct 2005 16:05:39 -0400
Hi Snorters, How is Bleeding Snort rules compare to Sourcefire Official rules in terms of accuracy in detecting intrusion attempts? Which set of rules are more practical to implement in a corporate environment? I'm thinking of implementing both sets of rules but I am afraid to run into many overlap alerts, has anybody try this before? What's the result is like? Many thanks! HinSuk __________________________________________________________________ Look What The New Netscape.com Can Do! Now you can preview dozens of stories and have the ones you select delivered to you without ever leaving the Top Home Page. And the new Tool Box gives you one click access to local Movie times, Maps, White Pages and more. See for yourself at http://netcenter.netscape.com/netcenter/
Current thread:
- Bleeding Snort rules and Sourcefire Official rules hchlai (Oct 25)
- <Possible follow-ups>
- RE: Bleeding Snort rules and Sourcefire Official rules Rowland, Krisa W ERDC-ITL-MS Contractor (Oct 25)
- Re: Bleeding Snort rules and Sourcefire Official rules Eric Hines (Oct 25)