snort logo

Snort Intrusion Detection System : Exposed

Presented by Yann Labour, <yayann@gmail.com>






What is an Intrusion Detection System?

Deploying an IDS on switched networks

Deploying an IDS : where to place it

Snort : some history

Snort's modes

  1. Packet sniffer
  2. Packet logger
  3. NIDS (Network Intrusion Detection System) mode
  4. Inline mode

Snort decomposed

  1. Packet sniffer decoder using pcap library
  2. Preprocessor plugins which check for malformations, anomalies, and non-compliance
  3. Detection engine which inspects traffic against rules base
  4. Output and alert module

Snort's preprocessors

Snort's rules set : where to get them

Example : Shelob

Conclusion

Snort is :

But :