[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <439992AF.2020508@csuohio.edu>
Date: Fri Dec 9 14:23:13 2005
From: michael.holstein at csuohio.edu (Michael Holstein)
Subject: Snort as IDS/IPS in mission-critical enterprise
network
> Most "enterprise" IDS products are built upon Snort code my friend.
> Snort is definately ready for whatever type of environment you put it
> in. Just make sure you follow the snort mailing list from time to time
> to keep up on new signatures that may not be added to the snort release.
And check ./contrib on snort, you'll find a ton of ways to automate the
rule updates. Bad idea to let it autonomously update (because if you HUP
snort and there's a bad rule, it dies) .. but easily made into a
once-a-week sort of thing.
~Mike.
Powered by blists - more mailing lists