Feed on
Posts
Comments

Category Archive for 'Snort'

Blacklisting with Snort

Managing IDS/IPS signatures can be a difficult task. Even with trained security professionals who are knowledgeable about their organization’s normal traffic pattern, most organizations configurations are continuously changing. New services and machines are put into place, creating new traffic patterns. While network IDS/IPS serve the function of finding evidence of nefarious activities, at large organization [...]

Read Full Post »

This week I had the pleasure of presenting two talks at the National Laboratories Information Technology (NLIT) 2009 Summit held in Oak Ridge, TN. Everyone involved was great and I had a fun time. Since the presentations have been posted to the NLIT site, I am free to post now.

The original [...]

Read Full Post »

Snort 3: The Next Generation

The folks at Sourcefire have been working hard at creating the next generation of Snort. Martin Roesch, captain of the brave development team, is boldly taking Snort where no pig has gone before. Cyberspace, the final frontier. Seriously, the core framework for Snort is being rewritten from the ground up. With [...]

Read Full Post »

Older Posts »

Bad Behavior has blocked 606 access attempts in the last 7 days.