Current Issue


Table of contents

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 12.0

Version 12.0 delivers every issue of Sys Admin from 1992 through 2006 and every
issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!

Sys Admin Magazine > Archives > 2001 > August 2001

Homebrew Intrusion Detection Systems

Chris Kuethe

his article is not about how to install Snort, tcpdump, NFR, or any other collection of bits that may reside in your $PATH. This article will discuss how to make all your tools and toys play nicely together. Other articles may have introduced you to the tools of the trade, Snort and tcpdump being two of the most popular tools. You've learned how to install them, but not much more than that. In brief, network intrusion detection is the "grey science" of analyzing network traffic anomalies. This implies that you have a relatively good baseline of normal traffic.

Generally, network intrusion detection systems are the collection of hardware, software, and personnel used to capture, display, and analyze traffic. Picking the best hardware and software is fairly simple. Network intrusion detection is certainly not infallible; the packets you see are interesting, but it is up to you to decide why they are interesting and whether this is cause for concern. As such, there are only general guidelines, not recipes. Intrusion detection can be a lot of fun, and even rudimentary intrusion detection capabilities can make the cleanup, and prevention, of a compromise a simpler task.

Many sites now have some form of traffic control in place, ranging from tcp-wrappered daemons to very restrictive packet filters and carefully written proxies. An excellent way to begin the journey into the world of intrusion detection is to tune your NIDS to watch for attempts to circumvent traffic policy and actual policy violations. With the freely available tools and some practice, you will be able to detect very subtle attacks.

Hardware

Network intrusion detection requires processing a huge amount of data, thus your system will need to be tuned for excellent disk and network I/O performance.




MarketPlace

Six Sigma Certification
100% Online-Six Sigma Certificate from Villanova - Find Out More Now.

Flowcharts from C/C++ code -- Free trial download
Understand C/C++ code in less time. A new team member ? Inherited legacy code ? Get up to speed faster with Crystal Flow for C/C++. Code-formatting improves readability. Flowcharts are integrated with code browser. Export flowcharts to Visio.

Discover WinDev 11 RAD
and develop 10 times faster ! ALM, IDE, .Net, PDF, 5GL, Database, 64-bit, etc. Free Express version

Domain Name Registrations, Web Hosting, Email
Pay less for Domain Names, Increase your company's bottom line - get a raise. Accredited domain name registrar, ZippyNames.us : Discount bulk transfers, email, webhosting, dedicated servers. Earn money as a domain name reseller - better discounts!

Wanna see your ad here?