nanog mailing list archives
RE: Re: Intrusion Detection recommendations
From: "Darden, Patrick" <Patrick.Darden () p66 com>
Date: Thu, 19 Feb 2015 14:01:50 +0000
These are all excellent tools for a dedicated knowledgeable network security person to use. The most important element being the dedicated knowledgeable network security person. --p -----Original Message----- From: NANOG [mailto:nanog-bounces () nanog org] On Behalf Of Jimmy Hess Sent: Saturday, February 14, 2015 12:57 PM To: Randy Bush Cc: North American Network Operators' Group Subject: [EXTERNAL]Re: Intrusion Detection recommendations On Sat, Feb 14, 2015 at 2:38 AM, Randy Bush <randy () psg com> wrote: Bro, SNORT, SGUIL, Tcpdump, and Wireshark are some nice tools. By itself, a single install of Snort/Bro is not necessarily a complete IDS, as it cannot inspect the contents of outgoing SSL sessions, so there can still be Javascript/attacks against the browser, or SQL injection attempts encapsulated in the encrypted tunnels; I am not aware of an open source tool to help you with SSH/SSL interception/SSL decryption for implementation of network-based IDS. You also need a hand-crafted rule for each threat that you want Snort to identify... Most likely this entails making decisions about what commercial ruleset(s) you want to use and then buying the appropriate subscriptions.
if you were comfortable enough with freebsd to use it as a firewall, you can run your traffic through, or mirror it to, a freebsd box running https://www.bro.org/ or https://www.snort.org/ two quite reasonable and powerful open source systems randy
-- -JH
Current thread:
- Re: Intrusion Detection recommendations, (continued)
- Re: Intrusion Detection recommendations Jimmy Hess (Feb 13)
- RE: Intrusion Detection recommendations Keith Medcalf (Feb 13)
- RE: Intrusion Detection recommendations Scavotto, Brian (Feb 18)
- Re: Intrusion Detection recommendations Joe Klein (Feb 19)
- Re: Intrusion Detection recommendations Randy Bush (Feb 14)
- Re: Intrusion Detection recommendations Jimmy Hess (Feb 14)
- Re: Intrusion Detection recommendations Charles N Wyble (Feb 14)
- Re: Intrusion Detection recommendations Rich Kulawiec (Feb 14)
- RE: Intrusion Detection recommendations Colin Bodor (Feb 15)
- RE: Re: Intrusion Detection recommendations Darden, Patrick (Feb 19)
- RE: Re: Intrusion Detection recommendations Darden, Patrick (Feb 19)
- Re: Intrusion Detection recommendations Jimmy Hess (Feb 14)