Active Members
TodayLast 7 Daysmore...


Resources » Articles/Knowledge Sharing » Computer & Technology

Snort Features


Posted Date:     Category: Computer & Technology    
Author: Member Level: Gold    Points: 5


Snort Features,alert vs log files, banyard,banyard waldo,adob,base,base local host,target-based intrusion detection,mysql and mysql client,stealth port scans, SMB probes, CGI attacks, buffer overflows, NetBIOS queries and NMAP



Snort is a NIDS open source software, Network intrusion detection system. It can be optimized to perform as a network intrusion detection and prevention system software, released by sourceforge.

Before installing snort in the windows or linux based operating system environment some dependency packages to be isntalled like adob, banyard,, base etc.

Following are the important features of Snort

* Snort is an open source, freeware IDS/IPS tool

* Source code of snort can be modified

* mysql and mysql client are needed to create databses and other snort related databases and query retrieval

* IPV6 is integrated into latest snort versions

* List of ports for port scan is available in the snort reports

* Snort can detect threats like stealth port scans, SMB probes, CGI attacks, buffer overflows, NetBIOS queries and NMAP

* Alert file indicates any suspicious or malicious attacks

* Log file is created with tcp dump formats of incoming and outgoing data packets

* Snort can be compared to Microsoft Security Bulletin MS08-068

* Snort's Unified2 output defines the nature of output file

* Snort can be used to inspect HTTP traffic

* Shared object rules are available in Snort and can be used

* Snort supports target-based intrusion detection

Network Intrusion Detection Prevention System
Related Resources:


Read related articles: Snort features    Installations    Softwares    Detection systems    


Did you like this resource? Share it with your friends and show your love!





Responses to "Snort Features"
Author: Joseph A    02 May 2010Member Level: Gold   Points : 1
Recent updates in snort features is, in the 2.8 release version snort has teh capability to handle the IPV6 options in the IP headers. IPV6 is the next generation to IPV6 so in previous releases IPV4 was supported and now snort can provide support to IPV6 also.


Feedbacks      

Post Comment:




  • Do not include your name, "with regards" etc in the comment. Write detailed comment, relevant to the topic.
  • No HTML formatting and links to other web sites are allowed.
  • This is a strictly moderated site. Absolutely no spam allowed.
  • Name:   Sign In to fill automatically.
    Email: (Will not be published, but required to validate comment)



    Type the numbers and letters shown on the left.


    Next Resource: SQL Queries - Hospital Management System
    Previous Resource: The two computer viruses that shook the world
    Return to Resources
    Post New Resource
    Category: Computer & Technology


    Post resources and earn money!
     
    More Resources
    Popular Tags   Tag posting guidelines   Search Tags  
    Snort Features  .  Alert vs log files  .  Banyard  .  Adob  .  Banyard waldo  .  Base  .  Target-based intrusion detection  .  Base local host  .  Mysql and mysql client  .  SMB probes  .  Stealth port scans  .  CGI attacks  .  Buffer overflows  .  NetBIOS queries and NMAP  .  

    Awards & Gifts
    ISC Technologies, Kochi - India. Copyright © All Rights Reserved.