Google
 
 
Home

Main Menu
 Home
 Linux Articles
 FreeBSD Articles
 Apache Articles
 Perl Articles
 Other Articles
 Program Downloads
 Free Books
 News
 The Web Links
 Contact Us

Most Read
Automating SFTP using expect
FreeBSD PPTP VPN
SnortShorwall - Using Snort And Shorewall Together
Shorewall Router on Linux
Shorewall Stand Alone Firewall

Polls
Favorite Linux/BSD
Fedora
Mandrake
Debian
Slackware
Gentoo
Suse
FreeBSD
Other
  

Syndicate
Latest news direct to your desktop
RSS

Login Form
Username

Password

Remember me
Forgotten your password?
No account yet? Create one

Members Online
 Linux-BSD-Central Has a Total of 14202 Members   Members (14202) # Online
 We have 7 Guests Online. Guests 7
 We have 0 Users Online. Users 0

Online Users
No Users Online

Statistics
OS: Linux w
PHP: 5.2.17
MySQL: 5.1.56
Time: 19:19
Members: 14202
Hits: 1793832
News: 281
WebLinks: 15





Snort 2.3 features in CVS   PDF  Print  E-mail 
Contributed by Chad Brandt  
Friday, 17 September 2004
The new features planned for Snort-2.3 have been checked into CVS under the SNORT_2_3 branch. We're pretty excited about the new features! First on the list is Snort-Inline (woo!). This was a big accomplishment, and took the efforts of many people.

The inline feature set includes only the core inline functionality. This means that DROP, SDROP, and REJECT rule-types are supported. The detection plugin "replace" has also been included. A couple of new features were also added during the integration effort, which provides inline state and dropping packets with bad checksums. The Snort-Inline project will continue to develop new inline features, so for the latest advancements in inline functionality, please refer to the Snort-Inline project. Further documentation can be found in README.INLINE and the Snort-Inline website.

Next up is a new portscan detection engine - sfPortscan. This engine was developed to detect TCP/UDP/ICMP/IP protocol scans and sweeps. In addition to this, it detects decoy and distributed portscans, and can distinguish between filtered and unfiltered scans. When portscan alerts are generated, the details of the portscan are logged along with it. This information gives the analyst details on how many ports were scanned, ranges, number of ips scanned, ip ranges, and what ports were open on the target. For more information, please see README.sfportscan. The design and implementation was headed up by Dan Roelker, and included Marc Norton and Jeremy Hewlett.

This release also includes various bug fixes, please refer to the ChangeLog for further information. Also, please remember that this is not considered to be an official stable release or candidate. Standard CVS disclaimer applies. However, for those living on the bleeding-edge, we encourage you to check it out and give us feedback.

Lastly, we've updated the "Our Team" page. Check it out.

Thanks for your time, please let us know what you think!

Read More Details

Comments

Only registered users can write comments.
Please login or register.

Powered by AkoComment 1.0 beta 2!




 


 

Check out TwistByte - The best mobile apps available For awesome Android and IPhone applications!!