Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

Re: [Snort-sigs] Rule Set Completness

Subject: Re: [Snort-sigs] Rule Set Completness
Date: Tue, 09 May 2006 11:36:47 -0400
Gentoo-Wally and Erik Fichtner wrote:

1. Is the VRT set suppose to be a "complete" (for the lack of a better
word. Maybe adequate would be better?) rule set capable of independent
deployment. "Complete" meaning including rules for most known
vulnerabilities/attacks or...

No.  Of the fuzzy "sorta" variety of no.   It's complete in the sense that
if it doesn't detect something and you're a paying customer of sourcefire,
you can complain and alter that situation.

Well put. The BS signatures are an addition to the core sets from SF and
VRT. But I'd say they aren't an optional thing. There are some very
important sigs in the BS sets.

There are also some rather experimental and possibly dangerous and high
load sigs.

You SHOULD run the VRT or GPL snort set, Bleeding Snort, and the
Community set. But you should NEVER run any of those sets in their
entirety on any sensor without review. You need to look through them all
and make decisions. (Yes... ALL of them)

That is time consuming, and will give you a good migraine if you try to
do too many at once. But it's a necessary step to any IDS setup. You
MUST understand what you're watching for, and what you're not watching
for. Otherwise the data you get is meaningless if you are assuming the
absence of certain alerts means they aren't happening. When in fact you
aren't running the rules you think you are, or they don't do what you
assumed they did.

Once you get through the initial load, you just need to review the
changes, which come in emails to the snort-sigs and bleeding-sigs lists
(http://lists.bleedingsnort.com/mailman/listinfo/bleeding-sigs).

You should look at each sig before pushing it. Not necessarily that you
need to be able to understand and second guess the sigs writer. But that
you understand the sig's intention and use. Some are internal only,
external only, high risk nets, PHI/HIPAA nets, classified
environments... etc.


2. Would a "complete" or "more complete" set include the combination
of VRT+Community+BleedingEdge Snort. If so...

Yes.


DEFINITELY!!!

3. Would the combination of VRT+Community+BleedingEdge result in a lot
of duplicate signatures?

Of course it would.  Yes.

see also: OSSRC Rules Overlap Committee.


There are some dupes now. We are trying to work them out with the SF
folks via the overlap committee. It's slow at the moment. That committee
is just getting it's legs, and has a lot of work ahead of it. But have
faith, I know they'll get into motion soon!

The number of dupes is not significant. You aren't going to be putting
significant load on a sensor unnecessarily. Some, yes, but not a lot if
you do a good review of sigs before you make the initial load.

Matt



--------------------------------------------
Matthew Jonkman, CISSP
Senior Security Engineer
Infotex
765-429-0398 Direct Anytime
765-448-6847 Office
866-679-5177 24x7 NOC
http://my.infotex.com
http://www.infotex.com
http://www.bleedingsnort.com
--------------------------------------------





-------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>