IDS mailing list archives
Re: OSSIM Fedback
From: Stefano Zanero <zanero () elet polimi it>
Date: Mon, 12 Jun 2006 23:06:24 +0200
Koolk3 wrote:
I am looking for some feedback on the usefulness and practicaility (interms or maintenance and configuration) of this software. I am mainly interested in OSSIM as a corelation tool / log analysis for now.
We studied OSSIM in order to use it as a framework for implementing our own correlation algorithms. My experience is partially negative, in particular for the lack of documentation on installation and software internals. Additionally, the source code is intentionally complex and undocumented, to avoid forking or reuse... which is quite curious for a GPL software.
Has anyone tried the latest version of the product (0.9.9)?
No, we didn't, we tested earlier versions.
Any feedback on installation and usability would be great.
Installation is quite difficult unless you use the provided debian packages. Installing it clean on a Gentoo or name-your-distro box is (used to be, at least) a mess. ONCE INSTALLED, the software is very good, not to say excellent, with good look and feel and usability. I like it a lot. But a software I cannot expand, extend or troubleshoot easily is very much the contrary of what I look for in a GPL software. Stefano ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
Current thread:
- OSSIM Fedback Koolk3 (Jun 12)
- Re: OSSIM Fedback Stefano Zanero (Jun 13)
- Re: OSSIM Fedback Dominique Karg (Jun 13)
- Re: OSSIM Fedback Stefano Zanero (Jun 16)
- Re: OSSIM Fedback Dominique Karg (Jun 13)
- RE: OSSIM Fedback Mark Lists (Jun 13)
- <Possible follow-ups>
- Re: OSSIM Fedback zmaster zhang (Jun 13)
- Re: OSSIM Fedback Stefano Zanero (Jun 13)