|
|
Choosing A Webhost: |
Re: P0F in Snort?: msg#00163security.ids.snort.bleedingsnort
I am kind of surprised that no one from SourceFire has commented, but that may be because of "quiet period" restrictions. Snort is becoming more and more target based (see Frag3 and the experimental Stream5). Right now, target information is only updateable via a change to the snort.conf and a restart (HUP). I hate to put words in Marty's mouth, but from what I understand, one of the big additions to snort 3.0 will be an interactive "command line", that will let other applications (think RNA) update target information on the fly. So, Matt, yeah I think others have definately thought about what you are wondering, and I expect it's already being worked on (at least to some degree). I don't think it's a bad idea to do something yourselves though (I think it's a great idea). I think there are a couple of reasons why SourceFire isn't putting the OS (or application) detection inside Snort like you've suggested. First is probably performance. It's pretty obvious that commercial products have to perform in the multi-gig space and I don't think Marty wanted to stop at OS detection. So, while OS detection in multi-gig with might be feasible, I doubt application detection is. A second reason is business. RNA is a huge piece of SourceFire (one might say that it is THE piece that makes SourceFire), so even if they could move RNA capabilities "into" snort, there is no way it's going to happen (and understandably so). Anyway, it'd be great to start seeing contributions to the snort codebase from outside of SourceFire again. Bammkkkk On 1/27/07, Matt Jonkman <jonkman-WwB1pFISwSkm7effSn6vN9HuzzzSOjJt@xxxxxxxxxxxxxxxx> wrote: Stray thought: ANyone ever seen or thought about integrating p0f into -- sguil - The Analyst Console for NSM http://sguil.sf.net
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | RE: P0F in Snort?, Matt Jonkman |
|---|---|
| Next by Date: | Re: P0F in Snort?, Bamm Visscher |
| Previous by Thread: | Re: P0F in Snort?, Bamm Visscher |
| Next by Thread: | RE: P0F in Snort?, Matt Jonkman |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |