LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


View Poll Results: Prelude VS Snort
Prelude 1 8.33%
Snort 11 91.67%
Voters: 12. You may not vote on this poll

Reply
  Search this Thread
Old 08-25-2004, 10:51 AM   #1
subaruwrx
Member
 
Registered: Mar 2004
Distribution: Ubuntu Feisty
Posts: 641

Rep: Reputation: 30
Intrusion Detection Systems


What are the significant difference between them and which do you guys prefer?
 
Old 08-25-2004, 12:54 PM   #2
Pcghost
Senior Member
 
Registered: Feb 2003
Location: The Arctic
Distribution: Fedora, Debian, OpenSuSE and Android
Posts: 1,820

Rep: Reputation: 46
I have never used prelude, as snort has been very good to me and I haven't found a reason to look elsewhere. Buy the Snort book from syngress and you can set up a mean IDS.
 
Old 08-25-2004, 02:05 PM   #3
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
Your poll makes absolutely no sense. X vs Y? What are your grounds for this comparison? What makes one better than another? You can't just ask a question and not give us your own views.
 
Old 08-27-2004, 01:06 AM   #4
subaruwrx
Member
 
Registered: Mar 2004
Distribution: Ubuntu Feisty
Posts: 641

Original Poster
Rep: Reputation: 30
I thought both perform the same task?

I'm just asking for opinions and recommendations before deciding which one to pick up.
 
Old 08-27-2004, 12:28 PM   #5
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Prelude also does HIDS if my recollection is correct. It has a little bit wider scope of coverage than Snort. On the other hand, Snort detects a lot more type of network attacks than Prelude does. It really depends on what you're trying to accomplish.
 
Old 08-31-2004, 07:31 PM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Prelude differs from Snort in that it uses a server-client (agent) setup. Prelude can do (or has hooks to) do more than be an (distributed) IDS agent: it can do filesystem integrity checking (like Aide, Samhain, Osiris, Integrit, tripwire) and IIRC rule-based policying (or interaction with) Niels Provos' Systrace. Both are similar in the fact they only do (mainly static) signature or rule-based matching (exaggerating), meaning there's no extensive built-in analysis and no decision logic to for instance automate the next step and (intelligently) correct or actively block traffic. Signature and rule-based also means in this respect that your detection capabilities are as strong as the rulesets and signatures you build. AFAIK products like Forestorm, Prelude etc etc are lagging behind compared to Snort when it comes to active community-based rule development (take a look on the snort-signatures mailinglist).

One of the things typically *NIX is to have one binary perform one task, and perform that task well. For reasons of widespread acceptance, large support community, active development, maturity, performance and the one taks thing I choose Snort anytime.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
intrusion detection fakie_flip Linux - Security 4 08-19-2005 05:24 PM
Intrusion Detection L1nuxbug Linux - Security 4 07-21-2004 05:20 AM
Intrusion Detection!!! egyptian Linux - Security 2 04-02-2004 11:37 AM
Intrusion Detection? matador Linux - Security 5 09-03-2003 04:44 AM
Intrusion Detection Policy WeNdeL Linux - Security 3 05-15-2003 05:46 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:54 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration