Snort mailing list archives

Re: Test Snort Performance


From: "Davison, Charles Robert" <cdaviso1 () vols utk edu>
Date: Sat, 19 Dec 2015 15:51:43 +0000

This should be a good list of testing things:

š  Commercial
š  Ixia Breaking Point (Security Testing)
š  Nessus (Vulnerability Scanner)
š  Spirent (Security Testing)
š  Open Source
š  IDS Wakeup<http://www.hsc.fr/ressources/outils/idswakeup/> (IDS Testing)
š  Hping<http://www.hping.org/> (Packet Crafting)
š  NMAP<https://nmap.org/> (Port Scanning)
š  Nikto<https://cirt.net/Nikto2> (Web Vulnerability Scanner)
š  Ostinato<https://code.google.com/p/ostinato/> (Packet Crafting)
š  Packeth<http://packeth.sourceforge.net/packeth/Home.html> (Packet Crafting)
š  Pytbull<http://pytbull.sourceforge.net/> <http://pytbull.sourceforge.net/> (IDS Testing)
š  TCPreplay<http://tcpreplay.synfin.net/> (IPS/IDS Testing)
š  Tomahawk<http://tomahawk.sourceforge.net/> (IPS/IDS Testing)


From: Ali Masoudi [mailto:masoudi1983 () gmail com]
Sent: Saturday, December 19, 2015 12:58 AM
To: snort-users () lists sourceforge net
Subject: [Snort-users] Test Snort Performance

Hi
I have a Centos system which I compiled and installed snort on. I want to perform a performance test with custom set of 
rules before deploy the system. With using of iperf and some edited pcap file. I ran some tests but they're not enough.
As for pcap file, I download it from internet and I edited MAC & IP addresses using tcpwrite to match source and 
destination. but destination system did not see entire traffic within pcap file.
Is there any tool to test snort performance? Or should I use traffic generators available in internet?
Any help would be appreciated. Sorry for my poor English.
Best Regards
Ali
------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: