|
Re: P0F in Snort?: msg#00175security.ids.snort.bleedingsnort
As a p0f lover, I guess I'll chime in here. I think that an external p0f process that wrote to a DB for lookups would be the most extensible for doing things like writing custom reports on what OS's are attacking, etc., and possibly feeding into other apps. However, I think that even the small task of doing a SELECT from the database would be an unacceptable performance loss. I think that realistically, a preprocessor would be the only way to go. As I understand it, the new stream5 API should have all the tools we need to write a multi-packet p0f preprocessor. Also, I don't think that the online database lookups would be worth it, I would suggest simply updating the p0f sigs with the Bleeding sigs (or some other method of incremental mass updates). I suppose that the other option would be to convert p0f sigs _into_ Bleeding sigs and just run them as normal noalert rules. That would make setting flowbits a lot easier, but that is a LOT of sigs. You could, however, pick and choose some. So Matt's example of XP sending mail would work if you just wrote a sig that detects XP and then the follow up to alert when the XP flowbit is set. I think that running p0f along with Netflow stats, etc., is a very necessary part of the network forensics toolkit. I also recommend something like urlsnarf (or a backend connection to your web cache/nanny) to create an easy-to-lookup repository of what web events occurred in relation to your Snort alerts. --Martin On 1/29/07, Matt Jonkman <jonkman-WwB1pFISwSkm7effSn6vN9HuzzzSOjJt@xxxxxxxxxxxxxxxx> wrote: Michael Scheidell wrote: |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Stormy P2P bot Sigs -- may be SKYPE ?: 00175, Matt Jonkman |
|---|---|
| Next by Date: | Re: P0F in Snort?: 00175, Mike Guiterman |
| Previous by Thread: | Re: P0F in Snort?i: 00175, Matt Jonkman |
| Next by Thread: | Re: P0F in Snort?: 00175, Blake Matheny |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |