ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Intrusion Detection System experience - Snort or others?

    IT Discussion
    snort ids security
    5
    8
    1.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Mike DavisM
      Mike Davis
      last edited by scottalanmiller

      Does anyone run an IDS? I'm working with a SonicWall firewall and primarily concerned with the traffic hitting the remote desktop server since it's the only incoming port. I'm also interested in looking for suspicious traffic leaving our network in the even that a computer on the inside got hacked and was calling home/providing remote access.

      Is anyone running Snort that can comment on it? I'm not against a commercial product if there is something that works well.

      WrCombsW FrostyPhoenixF 2 Replies Last reply Reply Quote 1
      • WrCombsW
        WrCombs @Mike Davis
        last edited by

        @Mike-Davis new to IT ; what is "IDS" ?
        and what is "Snort"?

        gjacobseG Mike DavisM 2 Replies Last reply Reply Quote 0
        • FrostyPhoenixF
          FrostyPhoenix @Mike Davis
          last edited by

          @Mike-Davis Hi there!
          So while there are a bunch of software that does it (Carbon Black by Bit9, McAfee HIPS, etc)

          I'd like to suggest my product...Jentu.

          What Jentu does is stream the desktop to a workstation internally, behind a secured network connection, and by doing so...bypasses the hard drive on the workstation.
          What that means is...with no hard drive at the workstation, means no platform for someone to put malware/cryptoware/spyware on your machine...as these require a hard drive to install into and operate out of.

          No other software on the planet can do that.

          Would you be interested in learning more?

          1 Reply Last reply Reply Quote 0
          • gjacobseG
            gjacobse @WrCombs
            last edited by

            @WrCombs said in Intrusion Detection System experience - Snort or others?:

            @Mike-Davis new to IT ; what is "IDS" ?
            and what is "Snort"?

            IDS - Intrusion Detection System.

            Snort would be a system or software .

            WrCombsW 1 Reply Last reply Reply Quote 0
            • dafyreD
              dafyre
              last edited by

              Snort is good for this... Another one that is also good for this is Suricata (https://oisf.net/suricata/)

              @WrCombs -- IDS is Intrusion Detection System (and IPS is Intrusion Prevention System)... IDS systems will alert you in various ways that something has happened that you set rules up for.

              An IPS system will actively try to block things that you set rules up for.

              Snort and Suricata can both be an IPS or IDS...

              1 Reply Last reply Reply Quote 0
              • Mike DavisM
                Mike Davis @WrCombs
                last edited by

                @WrCombs said in Intrusion Detection System experience - Snort or others?:

                @Mike-Davis new to IT ; what is "IDS" ?
                and what is "Snort"?

                Welcome to IT. You can get quick answers about what acronyms are and other stuff by googling it. IDS = Intrusion Detection System. It's a system that looks at what normal network traffic looks like and tries to find out of the ordinary traffic to indicate that you might have unauthorized access going on in your network among other things.

                1 Reply Last reply Reply Quote 1
                • dafyreD
                  dafyre
                  last edited by

                  @Mike-Davis -- I ran Suricata instead of Snort for a couple of years and it was excellent.

                  1 Reply Last reply Reply Quote 0
                  • WrCombsW
                    WrCombs @gjacobse
                    last edited by

                    oh okay! thanks guys. @Mike-Davis @gjacobse @dafyre

                    1 Reply Last reply Reply Quote 0
                    • 1 / 1
                    • First post
                      Last post