Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: [Snort-users] only the "important stuff" |
|---|---|
| Date: | Tue, 26 Oct 2004 12:56:17 -0700 |
Steven and Marc, It is a good idea to customize your signatures in order to limit the alerts only to those interesting to you. However, you are still likely to receive too many false positives and an enormous amount of data that is too difficult to analyze. SFS (Securimine for Snort) is a FREE tool designed to solve this problem exactly. SFS can be downloaded from http://www.securimine.com/download.html (If your boss is looking for a concise short report that presents the alerts that happen today which deviate from the normal stream of alerts - SFS is the tool you are looking for). In more details, SFS is an automatic analysis tool designed to provide reports of the POTENTIALLY MOST CRITICAL threats your system is facing. SFS automatically creates a model based on the behavior of your specific system. The analysis is done based on this model and the result is a concise report of the top threats. Based on the model, a normal behavior will be assigned low threat level which means you can ignore it. Any abnormal behavior will be assigned a higher threat level. At the end of the day, the report is easy to read and gives you the answer to your question: "Is there a real threat on my system?" SFS is very easy to install and it is FREE. For additional information including screen shots, please visit www.securimine.com Good Luck, Orit Vidas www.securimine.com -----Original Message----- Date: Tue, 26 Oct 2004 10:15:31 -0700 (PDT) From: SN ORT <snort_on_acid@yahoo.com> Subject: RE: [Snort-users] only the "important stuff" To: Snort Users <snort-users@lists.sourceforge.net>, steven.crandell@gmail.com What?! You mean, send him all of the positive alerts? Impossible without human intervention/correlation. You could move some sensors back or set some variables that look at only important machines, or even setup another instance of Snort that runs only custom signatures you're sure never produce false positives/negative..etc, but then you could very well miss some legitimate break-ins. You could also try to customize the IDS so that each signature is customized to vulnerable servers. IOW, why would I want to receive an IIS vulnerability alert when my server is running apache? So I would set a var $apache_servers=IPaddress(range) and then set each Apache signature to destination = "$apache_servers", and at the same time have the IIS signatures only relate to IIS servers. Wow, there's a concept. Nah, you'd have to have a brain look at those first, and then send them to your presidente (although products like from ISS contain correlation capabilities) Cheese! Marc -- __--__-- Message: 9 Date: Tue, 26 Oct 2004 09:34:56 -0700 From: Steven Crandell <steven.crandell@gmail.com> Reply-To: Steven Crandell <steven.crandell@gmail.com> To: snort-users@lists.sourceforge.net Subject: [Snort-users] only the "important stuff" Hi all, I have snort running the way I want it to run, etc. I'm also using logcheck to watch the logs and email me when someone exceeds my thresholds. Anyway, I'm pretty satisfied with how all of that is working. This morning the president of the co. has asked that he -not- receive the day to day alerts and would only like to receive alerts on "successful" intrusions. Are there certain rules that would never be triggered unless someone actually gets into a monitored system? Or anything along those lines? I know this is a little off the wall, but any help/suggestions would be greatly appreciated. regards, -- Steven Crandell steven.crandell@gmail.com __________________________________ Do you Yahoo!? Yahoo! Mail Address AutoComplete - You start. We finish. http://promotions.yahoo.com/new_mail ------------------------------------------------------- This SF.Net email is sponsored by: Sybase ASE Linux Express Edition - download now for FREE LinuxWorld Reader's Choice Award Winner for best database on Linux. http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [Snort-users] only the "important stuff", Jacques Brierre |
|---|---|
| Next by Date: | [Snort-users] Hunting down P2P users, Pedro Fortuna |
| Previous by Thread: | RE: [Snort-users] only the "important stuff", Jacques Brierre |
| Next by Thread: | [Snort-users] ack packets and data sequence, Jeffrey Starin |
| Indexes: | [Date] [Thread] [Top] [All Lists] |