Snort mailing list archives

Re: NetBios rules


From: "Jefferson, Shawn" <Shawn.Jefferson () bcferries com>
Date: Fri, 19 Jun 2009 11:58:01 -0600

Hi Nigel,

Yes, I am running the latest version of Snort with the DCE2 preprocessor. I just wanted to verify there wasn't anything 
I needed to do otherwise with the rule files/snort conf.  Since these rules are the heaviest hitters in my environment, 
I wanted to double check that they were the latest and most optimized.

-----Original Message-----
From: Nigel Houghton [mailto:nhoughton () sourcefire com] 
Sent: June 19, 2009 10:36 AM
To: Snort Users
Subject: Re: [Snort-users] NetBios rules

On Fri, Jun 19, 2009 at 1:07 PM, Jefferson,
Shawn<Shawn.Jefferson () bcferries com> wrote:
Hi,

I recently setup some rule profiling on one of my snort sensors, and I
noticed these rules taking quite a bit of time:
   Num      SID GID     Checks   Matches    Alerts           Microsecs
Avg/Check  Avg/Match Avg/Nonmatch
   ===      === ===     ======   =======    ======               =====
=========  ========= ============
     6     3053   1      71519         0         0
300498        4.2        0.0          4.2
     7     3045   1      71519         0         0
300498        4.2        0.0          4.2
     8     3057   1      71519         0         0
300498        4.2        0.0          4.2
     9     3049   1      71519         0         0
300498        4.2        0.0          4.2
    10     3051   1      71519         0         0
298919        4.2        0.0          4.2
    11     3043   1      71519         0         0
298919        4.2        0.0          4.2
    12     3055   1      71519         0         0
298919        4.2        0.0          4.2
    13     3047   1      71519         0         0
298919        4.2        0.0          4.2

They all seem to be NetBIOS rules.  With the new DCE2 preprocessor are these
rules going to disappear (or be changed) ?

--
Shawn Jefferson, Security Analyst
British Columbia Ferry Services Inc.
Tel: (250) 978-1508
Fax: (250) 405-3533
Shawn.Jefferson () bcferries com | www.bcferries.com


------------------------------------------------------------------------------
Crystal Reports - New Free Runtime and 30 Day Trial
Check out the new simplified licensing option that enables unlimited
royalty-free distribution of the report engine for externally facing
server and web deployment.
http://p.sf.net/sfu/businessobjects
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



Already done for all these rules. Are you not running the latest
version of snort with dcerpc2?

-- 
Nigel Houghton
Head Mentalist
SF VRT
http://vrt-sourcefire.blogspot.com && http://www.snort.org/vrt/
------------------------------------------------------------------------------
Are you an open source citizen? Join us for the Open Source Bridge conference!
Portland, OR, June 17-19. Two days of sessions, one day of unconference: $250.
Need another reason to go? 24-hour hacker lounge. Register today!
http://ad.doubleclick.net/clk;215844324;13503038;v?http://opensourcebridge.org
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

------------------------------------------------------------------------------
Are you an open source citizen? Join us for the Open Source Bridge conference!
Portland, OR, June 17-19. Two days of sessions, one day of unconference: $250.
Need another reason to go? 24-hour hacker lounge. Register today!
http://ad.doubleclick.net/clk;215844324;13503038;v?http://opensourcebridge.org
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: