LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-13-2012, 08:15 AM   #1
lamletoi
Member
 
Registered: Oct 2011
Posts: 46

Rep: Reputation: Disabled
Ask about snort rule


Hi everybody,
I am a newbie with IDS,i have just setup snort on Centos 6.
But i was very superise when i saw all rule in snortrule-snapshot were commented by "#".
Do i have to remove # in all line of rule when run snort.
Its so bad.

Last edited by lamletoi; 05-13-2012 at 08:18 AM.
 
Old 05-13-2012, 02:54 PM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
The rules that are in use should wind up in a place like /etc/snort/rules. When I looked at the file snortrule-snapshot, which was used to initially compile snort, the zip file contained the list of rules that goes into the aforementioned directory. What I noticed, when I looked in response to your question, is that many rules, but not all are commented out. I think that there a few foreces at work here. One Snort tends to generate a lot of false positives and the rules are very much in flux. I suspect that when rules are updated that old rules are simply commented out rather than deleted. Two, Snort is fairly CPU intensive in it's processing and the more rules that is it trying to compare against, the more worse it gets. Consequently, I think the developers try to achieve a good balance between rules that are effective and having too many rules.

Ultimately, to make the very best use of snort, you will likely need to learn to write rules and match them to the special cases of your system. Until then, the base snort rules, plus those from emerging threats should give you a pretty solid base to work with.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Snort - DynamicPlugin: Rule [##] not enabled in configuration, rule will not be used mhollis Linux - Software 3 08-29-2011 06:06 PM
[SOLVED] Snort Rule for Buffer overflow Fracker Linux - Security 1 02-16-2010 09:54 AM
Help with my snort rule set PixelCloud Linux - Security 1 07-17-2004 01:35 PM
snort rule update script netmon Linux - General 1 10-03-2003 06:31 PM
Snort, test rule, XST unSpawn Linux - Security 0 01-22-2003 06:53 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration