IDS mailing list archives

Re: newbie quetsions


From: Jose Maria Lopez <jkerouac () bgsec com>
Date: 03 Jan 2005 14:27:54 +0100

El vie, 24 de 12 de 2004 a las 16:07, Andrey Todorov escribiC3:
Hi People,
I tried several times to subscribe myself to "Security Basics" mailing
list to ask my questions, but didn't succeed. Excuse me if my
questions 
aren't adequate to "Focus IDS" mailing list!

I'll be very gratefull if you share your opinion with me for the 
following situation. I have small network (5 PCs) behind one Linux box
(iptables firewall , Pentium I 166Mhz, 32MB RAM, 4GB HDD) and want to 
increase security for this network.

    1. Do I need IDS?

In this days I think *everyone* needs an IDS, obviously I'm
talking if they want to be aware of all the threats that comes
from the internet. It's not really something you need, but
probably something you want. And it can be as problematic as
you want. You can simply take a look at the data it logs to
be aware of the danger or you can do some more work and tune
it to log all the attacks to your network. Obviously that's
just my opinion.

The only matter I see with your configuration it's that the
machine you are using as a firewall it's not enough to run
snort in a confortable way, you need some more power, at least
more memory.

    2. What do you think about Snort? Can I find easy maintainable 
free/opensource IDS then Snort?

I bet the best Opensource IDS you can find it's snort, and with
more reasons now that it's being merged with the snort-inline
project. You can also try Portsentry, that it's a different
approach to the IDS field.

    3. What IDS literature should I read?

You have plenty of it in the snort.org site.


Thank you in advance!

Andrey


Regards.

-- 
Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
jkerouac () bgsec com
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com
ESPAÑA

The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
                -- Jack Kerouac, "On the Road"


--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from 
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
--------------------------------------------------------------------------


Current thread: