Open source network intrusion prevention
Snort - Software Review
Review date: 01.10.2011

Description :

Created in 1998 by Martin Roesch, this robust and free IDS allows you to detect thousands of worms and suspicious behavior. Moreover, you can create new rules or modify existing ones to detect issues. It provides the source IP addresses for each of the IDS events. Being constantly updated with new features. Written in C, it also enables several configurable command line options.

Screenshots

Price :

Free license


Advanced Features :

  • Available to anyone without any cost
  • Sniffer and packet logger
  • Can run on Windows platform
  • Packet capture capability
  • Integrates into many commercial products
  • False negatives are very low
  • Host-based IDS. Offers protocol analysis
  • Supports logging to MySQL, ODBC databases
  • IPv6 support
  • Can be customized any way you need

Review :

This lightweight IDS solution enables to detect OS fingerprinting attempts, malicious code, stealth port scans and buffer overflows. This based network intrusion detection service enables you to access to your alert reports and device activities. Provides TCP stream reassembly and stateful analysis.

Main software features: Once Snort is running on your server, you can check many of the attempted attacks on your machines. You can also add Oinkmaster, a popular rule management tool, written is Perl language.

Main features
Easy to use, Snort is able to read in a TCPDump trace and run against a rule set

Main Benefits
Alerts against unwanted internal or external network. In NIDS mode, Snort allows you to match packet bytes against a set of rules. In addition to that, these C routines are compiled into a library.

Overall, with its add-ins and ons, Snort has to be one of our favorites. Moreover, this open source tool can act as a sniffer and can be deployed rapidly within your network.

Resources - Other Intrusion Detection systems (Shareware and software)
  • SATAN - Security Administrator Tool for Analyzing Networks
  • Nessus - Vulnerability scanner
  • TCPdump - Command-line packet analyzer
  • Snort Setup Guides - Comments and questions and faqs
Please note that Unix users may also need the Perl Compatible Regular Expressions library.
Related to Site Reviews
Advertisement



2011 Internet Security - Sponsored Sites

GFI Software - Leading developer of network security, content security and messaging software. Its product range includes email content exploit checking and anti-virus software; security scanning and patch management tools.

Refog Personal Monitor - is a multifunctional keyboard tracking software that is widely used by both regular users and IT security specialists to record keystrokes. Even if users delete their browser's history,