Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Users
[Top] [All Lists]

RE: [Snort-users] Bleeding Snort rules and Sourcefire Official rules

Subject: RE: [Snort-users] Bleeding Snort rules and Sourcefire Official rules
Date: Tue, 25 Oct 2005 15:11:39 -0500
HinSuk,

 

I run both sets of rules.  I do not find too much overlap - usually when one
is turned into an "official" rule - then they pull it out of the bleeding set
pretty quickly.  

 

Krisa

 

________________________________

From: snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of
hchlai@netscape.net
Sent: Tuesday, October 25, 2005 3:06 PM
To: snort-users@lists.sourceforge.net
Subject: [Snort-users] Bleeding Snort rules and Sourcefire Official rules

 

Hi Snorters,

 

How is Bleeding Snort rules compare to Sourcefire Official rules in terms of
accuracy in detecting intrusion attempts? Which set of rules are more
practical to implement in a corporate environment? I'm thinking of
implementing both sets of rules but I am afraid to run into many overlap
alerts, has anybody try this before? What's the result is like?

 

Many thanks!

 

HinSuk

 

________________________________

Look What The New Netscape.com Can Do!
Now you can preview dozens of stories and have the ones you select delivered
to you without ever leaving the Top Home Page. And the new Tool Box gives you
one click access to local Movie times, Maps, White Pages and more. Click to
test drive. 

<Prev in Thread] Current Thread [Next in Thread>