Snort mailing list archives

Re: Snort architecture


From: Johnny Venter <Johnny.Venter () zoho com>
Date: Wed, 11 Jul 2012 13:09:18 -0400

It depends where you are placing your sensor(s) and what type of traffic you are attempting to monitor.

Will the sensor monitor incoming traffic in the DMZ or monitor your internal server farm. 

I agree with Tony.  The Snort books do not go into much detail about placement because that is something the network 
administrator needs to identify for him/herself depending on their network and specific needs.

--
Johnny

On Jul 11, 2012, at 11:47 AM, Pratik Narang wrote:

Dear Snort users,

Can anyone please help me out with Snort's architecture-  based on their own knowledge, or documentation or books or 
references available for it. I wish to understand the architecture at a high level of abstraction and understand the 
various modules, their dependencies, what part of the source code does what, where does the signature engine lie, 
where is the anomaly engine, etc.

Thanks...
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!



------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: