Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: newbie quetsions |
|---|---|
| Date: | Tue, 28 Dec 2004 00:33:00 -0500 |
Hi People,
Greetings. =)
I tried several times to subscribe myself to "Security Basics" mailing list to ask my questions, but didn't succeed. Excuse me if my questions aren't adequate to "Focus IDS" mailing list!
If it made it past the mods, then it's obviously welcome. ;) So no worries at all. [snip]
1. Do I need IDS?
That's a loaded question. No one *needs* and IDS, though it certainly comes in handy if you want to be proactive about your network security. =P I'd recommend it if you're curious or concerned about InfoSec, yes.
2. What do you think about Snort? Can I find easy maintainable free/opensource IDS then Snort?
Snort is an extremely well designed, full featured IDS package. It's pretty easy to setup and get the basics running, plus it could be done on the hardware you have available, assuming you don't use massive amounts of bandwidth. I wouldn't bother to look any further if you're just starting out with an IDS. Snort should do everything you need to have done and it's widely supported with tech support available all over (including on this list).
3. What IDS literature should I read?
Well, if you're going to be using Snort, then I'd highly recommend the user manual[1] as a good place to start. ;) There are also a variety of different FAQs, Reviews, and information on IDS in general out there. Some good beginning (but thorough) reading can be found at SANS[2]. WindowsSecurity.com also has a nice writeup[3]. Beyond those, pop over to Google and do some hunting. Searching for things like "IDS FAQ" or "what is IDS" will reveal hours of worthwhile reading. =) [1] - http://www.snort.org/docs/writing_rules/chap1.html [2] - http://www.sans.org/resources/idfaq/ [3] - http://www.windowsecurity.com/faqs/Intrusion_Detection/ -- Peace. ~G On Fri, 24 Dec 2004 16:07:30 +0100, Andrey Todorov <andreyt@gawab.com> wrote:
Hi People,
I tried several times to subscribe myself to "Security Basics" mailing
list to ask my questions, but didn't succeed. Excuse me if my questions
aren't adequate to "Focus IDS" mailing list!
I'll be very gratefull if you share your opinion with me for the
following situation. I have small network (5 PCs) behind one Linux box
(iptables firewall , Pentium I 166Mhz, 32MB RAM, 4GB HDD) and want to
increase security for this network.
1. Do I need IDS?
2. What do you think about Snort? Can I find easy maintainable
free/opensource IDS then Snort?
3. What IDS literature should I read?
Thank you in advance!
Andrey
--------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
--------------------------------------------------------------------------
-------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: help needed ..., Winged Dragon |
|---|---|
| Next by Date: | Re: [Snort-users] RE: Network Behaviour Anomoly Detection, Martin Roesch |
| Previous by Thread: | newbie quetsions, Andrey Todorov |
| Next by Thread: | Re: newbie quetsions, ken_i_m |
| Indexes: | [Date] [Thread] [Top] [All Lists] |