Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

Re: newbie quetsions

Subject: Re: newbie quetsions
Date: Tue, 28 Dec 2004 00:33:00 -0500
Hi People,

Greetings. =)

I tried several times to subscribe myself to "Security Basics" mailing
list to ask my questions, but didn't succeed. Excuse me if my questions
aren't adequate to "Focus IDS" mailing list!

If it made it past the mods, then it's obviously welcome. ;) So no
worries at all.

[snip]
    1. Do I need IDS?

That's a loaded question. No one *needs* and IDS, though it certainly
comes in handy if you want to be proactive about your network
security. =P I'd recommend it if you're curious or concerned about
InfoSec, yes.

    2. What do you think about Snort? Can I find easy maintainable
free/opensource IDS then Snort?

Snort is an extremely well designed, full featured IDS package. It's
pretty easy to setup and get the basics running, plus it could be done
on the hardware you have available, assuming you don't use massive
amounts of bandwidth. I wouldn't bother to look any further if you're
just starting out with an IDS. Snort should do everything you need to
have done and it's widely supported with tech support available all
over (including on this list).

    3. What IDS literature should I read?

Well, if you're going to be using Snort, then I'd highly recommend the
user manual[1] as a good place to start. ;) There are also a variety
of different FAQs, Reviews, and information on IDS in general out
there. Some good beginning (but thorough) reading can be found at
SANS[2]. WindowsSecurity.com also has a nice writeup[3].

Beyond those, pop over to Google and do some hunting. Searching for
things like "IDS FAQ" or "what is IDS" will reveal hours of worthwhile
reading. =)

[1] - http://www.snort.org/docs/writing_rules/chap1.html
[2] - http://www.sans.org/resources/idfaq/
[3] - http://www.windowsecurity.com/faqs/Intrusion_Detection/

--
Peace. ~G


On Fri, 24 Dec 2004 16:07:30 +0100, Andrey Todorov <andreyt@gawab.com> wrote:
Hi People,
I tried several times to subscribe myself to "Security Basics" mailing
list to ask my questions, but didn't succeed. Excuse me if my questions
aren't adequate to "Focus IDS" mailing list!

I'll be very gratefull if you share your opinion with me for the
following situation. I have small network (5 PCs) behind one Linux box
(iptables firewall , Pentium I 166Mhz, 32MB RAM, 4GB HDD) and want to
increase security for this network.

    1. Do I need IDS?
    2. What do you think about Snort? Can I find easy maintainable
free/opensource IDS then Snort?
    3. What IDS literature should I read?

Thank you in advance!

Andrey

--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
--------------------------------------------------------------------------



--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from 
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
--------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>