IDS mailing list archives
Re: newbie quetsions
From: Jose Maria Lopez <jkerouac () bgsec com>
Date: 03 Jan 2005 14:27:54 +0100
El vie, 24 de 12 de 2004 a las 16:07, Andrey Todorov escribiC3:
Hi People, I tried several times to subscribe myself to "Security Basics" mailing list to ask my questions, but didn't succeed. Excuse me if my
questions
aren't adequate to "Focus IDS" mailing list! I'll be very gratefull if you share your opinion with me for the following situation. I have small network (5 PCs) behind one Linux box (iptables firewall , Pentium I 166Mhz, 32MB RAM, 4GB HDD) and want to increase security for this network. 1. Do I need IDS?
In this days I think *everyone* needs an IDS, obviously I'm talking if they want to be aware of all the threats that comes from the internet. It's not really something you need, but probably something you want. And it can be as problematic as you want. You can simply take a look at the data it logs to be aware of the danger or you can do some more work and tune it to log all the attacks to your network. Obviously that's just my opinion. The only matter I see with your configuration it's that the machine you are using as a firewall it's not enough to run snort in a confortable way, you need some more power, at least more memory.
2. What do you think about Snort? Can I find easy maintainable free/opensource IDS then Snort?
I bet the best Opensource IDS you can find it's snort, and with more reasons now that it's being merged with the snort-inline project. You can also try Portsentry, that it's a different approach to the IDS field.
3. What IDS literature should I read?
You have plenty of it in the snort.org site.
Thank you in advance! Andrey
Regards. -- Jose Maria Lopez Hernandez Director Tecnico de bgSEC jkerouac () bgsec com bgSEC Seguridad y Consultoria de Sistemas Informaticos http://www.bgsec.com ESPAÑA The only people for me are the mad ones -- the ones who are mad to live, mad to talk, mad to be saved, desirous of everything at the same time, the ones who never yawn or say a commonplace thing, but burn, burn, burn like fabulous yellow Roman candles. -- Jack Kerouac, "On the Road" -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
Current thread:
- Re: newbie quetsions Jose Maria Lopez (Jan 03)
- <Possible follow-ups>
- Re: newbie quetsions Jason (Jan 06)
- Re: newbie quetsions Dave Aitel (Jan 06)
- Re: newbie quetsions (on how much Snort sucks) Martin Roesch (Jan 11)
- Re: newbie quetsions (on how much Snort sucks) Dave Aitel (Jan 11)
- Re: newbie quetsions (on how much Snort sucks) Martin Roesch (Jan 11)
- Re: newbie quetsions Dave Aitel (Jan 06)
- RE: newbie quetsions Julius Detritus (Jan 12)
- Re: newbie quetsions Rainer Duffner (Jan 17)
- About IPS testing (was: newbie quetsions) Julius Detritus (Jan 19)
- Re: About IPS testing Tod Beardsley (Jan 24)