Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] A complication with an unconventional use of Snort |
|---|---|
| Date: | Tue, 19 Sep 2006 17:06:33 +0100 |
Hi
-Leon
On 19 Sep 2006, at 16:49, bahdko@erols.com wrote:
I have snort sensors deployed in an uncommon scenario, and I'm having a complication I'm hoping someone could give me input on.
The first part of the process does not experience problems.
The data from the LAN is first gathered by a snort process that is run that just creates a binary file. The snort program that does this is started like so:
/usr/local/bin/snort -l /var/log/snort -bD -i eth1
This process results in a binary log file named something similar to snort.log.1126876613.
Then, when the Snort program has been restarted and the binary log file is closed, the second part of the process is as follows.
I use another instance of Snort to read this binary log file and re- log it into a fully-expanded ASCII format. An example command I use to do this is as follows:
/usr/local/bin/snort -dvCeq -K ascii -r /var/log/snort/snort.log. 1126876613 net 192.168.10.0/24 -D -l /var/log/asciilogs/
The result of this operation is that there are directories within / var/log/asciilogs that contain all of the packet information, in ASCII, from the binary file.
My problem is this:
During this second instance of Snort, Snort appears to take the entire binary log file, no matter how big it is, and steadily read the whole thing into memory as it processes it. I can watch in "top" as the memory and swap available on the machine are steadily sucked away until the amount of memory displacing the binary file size are represented, and then the process ends and frees up the memory.
Does Snort really have to do it this way and take all of that memory? I know that Snort is processing this file sequentially, more or less packet-by-packet, it would seem that it shouldn't be necessary to hold the entire file in memory the whole time.
I periodically have some binary log files that exceed the swap +memory of my sensor, and I can't process those because of the way Snort is doing this.
Thanks,
--Laura
---------------------------------------------------------------------- ---
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys -- and earn cash
http://www.techsay.com/default.php? page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
Leon Ward CISSP, SFCE Security Engineer UK Sourcefire (The originators of Snort) 400 Thames Valley Park Drive, Thames Valley Park Reading, RG6 1PT, United Kingdom
Tel: +44 (0) 1189 653 555 Mob: +44 (0) 7818 067 304 Fax: +44 (0) 1189 653 554
leon.ward@sourcefire.com
www.sourcefire.com www.snort.org
------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys -- and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-users] A complication with an unconventional use of Snort, bahdko |
|---|---|
| Next by Date: | Re: [Snort-users] Snort-users Digest, Vol 4, Issue 26, SN ORT |
| Previous by Thread: | [Snort-users] A complication with an unconventional use of Snort, bahdko |
| Next by Thread: | [Snort-users] Correct Link for the Snort Virtual Users Group, Mike Guiterman |
| Indexes: | [Date] [Thread] [Top] [All Lists] |