Snort mailing list archives
Re: Naming convention of Snort
From: Erek Adams <erek () theadamsfamily net>
Date: Wed, 13 Mar 2002 10:31:38 -0800 (PST)
On Wed, 13 Mar 2002, Jason Hammerschmidt wrote:
Why name Snort a NIDS when it's really a Host based IDS.. often being used as an attempted NIDS via Ethernet taps/port mirroring.
Ummm... A HIDS is something that actually sits on one box and _only_ looks at that one box. Snort is a NIDS, since it monitors network traffic and not host based processes/data. Since that's the case, the best way to use it would be with taps and/or mirrored ports.
So I don't start a flame war, I'm assuming NIDS is an inline, or inband IDS at the point of an interconnection from one network to another (like a router/firewall/single transparent bridge). Also, this is strictly a curiousity question, I very much like Snort.
Oh, don't worry about flame wars here. As long as you don't mention your OS is bigger than mine, we don't care. ;-) What you're really thinking of is a GIDS (Gateway IDS).
In various articles/docs, Snort is often referred to as lightweight, is this only because it's non commercial? I'm confused by this term, although it seems to be disapearing recently. Anyone?
The real reason is almost historical now... When Marty first wrote it, it was tiny and 'light'. Almost just a simple network packet grepper. Then as things got expanded--plugins being the main culprit--it started to get 'plumper'. It's still light and fast, but it now does things that it's orginal versions could only dream of. Cheers! ----- Erek Adams Nifty-Type-Guy TheAdamsFamily.Net _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Naming convention of Snort Jason Hammerschmidt (Mar 13)
- Re: Naming convention of Snort Chris Green (Mar 13)
- Re: Naming convention of Snort Erek Adams (Mar 13)
- <Possible follow-ups>
- Re: Naming convention of Snort Jason Hammerschmidt (Mar 13)
- Re: Naming convention of Snort Erek Adams (Mar 13)
- Re: Naming convention of Snort Leigh David Heyman (Mar 13)
- Re: Naming convention of Snort Chris Green (Mar 13)
- Re: Naming convention of Snort Erek Adams (Mar 13)
- Re: Naming convention of Snort counter . spy (Mar 13)
- RE: Naming convention of Snort Bob Walder (Mar 13)