Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: newbie quetsions |
|---|---|
| Date: | 03 Jan 2005 14:27:54 +0100 |
El vie, 24 de 12 de 2004 a las 16:07, Andrey Todorov escribiC3:
Hi People, I tried several times to subscribe myself to "Security Basics" mailing list to ask my questions, but didn't succeed. Excuse me if my
questions
aren't adequate to "Focus IDS" mailing list!
I'll be very gratefull if you share your opinion with me for the
following situation. I have small network (5 PCs) behind one Linux box
(iptables firewall , Pentium I 166Mhz, 32MB RAM, 4GB HDD) and want to
increase security for this network.
1. Do I need IDS?
In this days I think *everyone* needs an IDS, obviously I'm talking if they want to be aware of all the threats that comes from the internet. It's not really something you need, but probably something you want. And it can be as problematic as you want. You can simply take a look at the data it logs to be aware of the danger or you can do some more work and tune it to log all the attacks to your network. Obviously that's just my opinion. The only matter I see with your configuration it's that the machine you are using as a firewall it's not enough to run snort in a confortable way, you need some more power, at least more memory.
2. What do you think about Snort? Can I find easy maintainable free/opensource IDS then Snort?
I bet the best Opensource IDS you can find it's snort, and with more reasons now that it's being merged with the snort-inline project. You can also try Portsentry, that it's a different approach to the IDS field.
3. What IDS literature should I read?
You have plenty of it in the snort.org site.
Thank you in advance! Andrey
Regards. -- Jose Maria Lopez Hernandez Director Tecnico de bgSEC jkerouac@bgsec.com bgSEC Seguridad y Consultoria de Sistemas Informaticos http://www.bgsec.com ESPAÃA The only people for me are the mad ones -- the ones who are mad to live, mad to talk, mad to be saved, desirous of everything at the same time, the ones who never yawn or say a commonplace thing, but burn, burn, burn like fabulous yellow Roman candles. -- Jack Kerouac, "On the Road" -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: IDS event filtering, dcdave |
|---|---|
| Next by Date: | Re: IDS event filtering, M. Dodge Mumford |
| Previous by Thread: | Re: IDS event filtering, Stef |
| Next by Thread: | Re: newbie quetsions, Jason |
| Indexes: | [Date] [Thread] [Top] [All Lists] |