The Experts below are selected from a list of 24 Experts worldwide ranked by ideXlab platform

Eugene Albin - One of the best experts on this subject based on the ideXlab platform.

  • A Comparative Analysis of the Snort and Suricata Intrusion-Detection Systems
    Defense Analysis, 2010
    Co-Authors: Eugene Albin
    Abstract:

    Our research focuses on comparing the performance of two open-source intrusion- detection systems, Snort and Suricata, for detecting malicious activity on computer networks. Snort, the de-facto industry standard open-source solution, is a mature product that has been available for over a decade. Suricata, released two years ago, offers a new approach to signature-based intrusion detection and takes advantage of current technology such as process multi-threading to improve processing speed. We ran each product on a multi-core computer and evaluated several hours of network traffic on the NPS backbone. We evaluated the speed, memory requirements, and accuracy of the detection engines in a variety of experiments. We conclude that Suricata will be able to handle larger volumes of traffic than Snort with similar accuracy, and thus recommend it for future needs at NPS since the Snort Installation is approaching its bandwidth limits.

Albin Eugene - One of the best experts on this subject based on the ideXlab platform.

  • A comparative analysis of the Snort and Suricata intrusion-detection systems
    Monterey California. Naval Postgraduate School, 2011
    Co-Authors: Albin Eugene
    Abstract:

    Approved for public release; distribution is unlimited.Our research focuses on comparing the performance of two open-source intrusion-detection systems, Snort and Suricata, for detecting malicious activity on computer networks. Snort, the de-facto industry standard open-source solution, is a mature product that has been available for over a decade. Suricata, released two years ago, offers a new approach to signature-based intrusion detection and takes advantage of current technology such as process multithreading to improve processing speed. We ran each product on a multi-core computer and evaluated several hours of network traffic on the NPS backbone. We evaluated the speed, memory requirements, and accuracy of the detection engines in a variety of experiments. We conclude that Suricata will be able to handle larger volumes of traffic than Snort with similar accuracy, and thus recommend it for future needs at NPS since the Snort Installation is approaching its bandwidth limits

Eric S. Seagren - One of the best experts on this subject based on the ideXlab platform.

  • Installing Snort 2.6
    How to Cheat at Configuring Open Source Security Tools, 2007
    Co-Authors: Raven Alder, Angela Orebaugh, Josh Burke, Larry Pesce, Chad Keefer, Eric S. Seagren
    Abstract:

    This chapter discusses about choosing the appropriate operating system for use on a Snort sensor. It also explains the performance implications of the various components and subsystems of the physical sensor. Precaution has to be taken to harden Snort sensor to prevent it from being compromised, because it will be sitting at a critical point within the network. The chapter explains all the aspects regarding building a sensor, some real-world operating systems, and the pros and cons of each. It focuses the process of installing and configuring Snort. Integral to Snort Installation and configuration is the underlying operating system's means for package management and the ways to install and keep a system up-to-date. The chapter explores the usage of apt-get, RPM, portage, and binaries. After installing Snort, it has to be configured properly, so it explains about the files included in the Snort distribution that help Snort do its job. It also describes the various preprocessor and output plug-ins, and their configuration directives.

Raven Alder - One of the best experts on this subject based on the ideXlab platform.

  • Installing Snort 2.6
    How to Cheat at Configuring Open Source Security Tools, 2007
    Co-Authors: Raven Alder, Angela Orebaugh, Josh Burke, Larry Pesce, Chad Keefer, Eric S. Seagren
    Abstract:

    This chapter discusses about choosing the appropriate operating system for use on a Snort sensor. It also explains the performance implications of the various components and subsystems of the physical sensor. Precaution has to be taken to harden Snort sensor to prevent it from being compromised, because it will be sitting at a critical point within the network. The chapter explains all the aspects regarding building a sensor, some real-world operating systems, and the pros and cons of each. It focuses the process of installing and configuring Snort. Integral to Snort Installation and configuration is the underlying operating system's means for package management and the ways to install and keep a system up-to-date. The chapter explores the usage of apt-get, RPM, portage, and binaries. After installing Snort, it has to be configured properly, so it explains about the files included in the Snort distribution that help Snort do its job. It also describes the various preprocessor and output plug-ins, and their configuration directives.

  • Mucking Around with Barnyard
    Snort 2.1 Intrusion Detection, 2004
    Co-Authors: Andrew R. Baker, Raven Alder, Brian Caswell, Mike Poor, Stephen Northcutt, Jacob Babbin, Jay Beale, Adam Doxtater, James C. Foster, Toby Kohlenberg
    Abstract:

    This chapter discusses the ways to install, configure, and use Barnyard as part of a Snort Installation. With Barnyard deployed, Snort does not have to deal with the myriad of ways that the alerts need for getting formatted and dispatched. Instead, Snort can simply output the events using the unified output plug-in and Barnyard will handle the details of inserting them into a database, generating syslog. The most obvious situation in which to use Barnyard is when Snort is being used to monitor a high-speed network—the scenario envisioned when Barnyard was additionally developed. However, several other advantages can be realized by using Barnyard. For example, although Snort requires some level of root privileges to promiscuously sniff network traffic, Barnyard has no such requirement. Barnyard only needs to be able to read the unified files generated by Snort. Therefore, the security conscious users may want to use Barnyard to implement privilege separation.

Bezborodov Sergey - One of the best experts on this subject based on the ideXlab platform.

  • Intrusion Detection Systems and Intrusion Prevention System with Snort provided by Security Onion.
    Mikkelin ammattikorkeakoulu, 2016
    Co-Authors: Bezborodov Sergey
    Abstract:

    In this thesis I wanted to get familiar with Snort IDS/IPS. I used the Security Onion distribution with a lot of security tools, but I concentrated on Snort. Also I needed to evaluate Security Onion environment and check what features it provides for processing with Snort. During the work I needed to figure out the pros and cons of using Security Onion with Snort as a security system for network. I compared it with alternatives and briefly describe it. As result I installed Security Onion, work with the environment, configured different features, created and modified rules and so on. I think this thesis will be helpful for people who want to use IDS/IPS for their network, it should help them to choose IDS/IPS vendor, make Security Onion and Snort Installation, make comparison with another one and just get familiar with the network security tools. Also, this thesis can be a part of big research of network security tools, because now is impossible to find such detailed guides and literatures about any IDS/IPS tools. It is a good idea to combine many researches about it and make a good library. This thesis can be used for further development of Snort and Security Onion as it only on the development phase now, it will provide base for new researching with new versions