LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 02-24-2011, 12:01 PM   #1
Mark_667
Member
 
Registered: Aug 2005
Location: Manchester, England
Distribution: Ubuntu 12.04
Posts: 231

Rep: Reputation: 25
Snort and MS Threat Protection Manager


I work in a relatively small organisation of about 30 people (but with a complex network) and we've been looking to move our firewall to Microsoft's Threat Protection Manager on a mostly Windows network. I've been thinking we should have an IDS/IPS inside the firewall and I've been thinking about Snort in NIDS mode but have some basic questions:

1. Can anyone recommend a good web GUI for Snort?

2. Is it advisable to run both on the same machine? (Both from a POV of security and resources.)

3. Would Snort add any real benifit to using TPM?
 
Old 02-24-2011, 12:31 PM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Ubuntu 10.10, Slackware 64-current
Posts: 1,790

Rep: Reputation: 656Reputation: 656Reputation: 656Reputation: 656Reputation: 656Reputation: 656
For Snort, you can use Base as a GUI to monitor the status and work with the databases. There are several utilities for working with the rules, such as Oinkmaster and Barnyard. Putting Snort behind your firewall is a good choice. That way it will monitor what makes it through the firewall rather than everything that hits it. As long as you have the resources I don't see why you can't run the Snort and the GUI on the same machine. Here are some articles regarding running snort on a separate machine. After reading the article I settled on using a NIC card in stealth mode (not configured with an IP or anything) and set up a span port on the switch to capture all of the traffic on all of the machines. I think it works quite well. You will get a lot of false positives with the Snort so you will have to tune it. The pre-compiled rules seem to be a particular source of positives. You can suppress rules effectively using the threshold.conf file to filter a rule and even base it upon the source and / or destination IP rather than blocking the entire rule. You should also look into the emerging-threats rules. These seem to pick up a lot more cutting edge stuff than the base snort rules.

I am not familiar with TPM, so I can't really comment on it.
 
1 members found this post helpful.
Old 02-24-2011, 12:58 PM   #3
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, FreeBSD, OpenBSD, Mac OS X , Backtrack, Ubuntu on a Dell Mini 9
Posts: 780
Blog Entries: 8

Rep: Reputation: 155Reputation: 155
Quote:
1. Can anyone recommend a good web GUI for Snort?
There are several. BASE is tried and proven, but is actually rather complex in setting up (actually, they all are). Another is Sguil. Yet another is Snorby. Those are free. Since you're comparing to MS products, you probably can afford some commercial solutions also (they're probably cheaper than MS products, too): Aanval, Astaro, Splunk (mainly for correlation).

Quote:
2. Is it advisable to run both on the same machine? (Both from a POV of security and resources.)
You want to try to segregate those duties, if at all possible. In fact, you might want to spread out the snort backend (have one machine running the GUI and another running the database, and if your network is sprawling, you might even want to dedicate a machine to snort itself).

Quote:
3. Would Snort add any real benifit to using TPM?
Snort is very solid and is a proven product, as long as you know its capabilities. I'm not familiar with TPM, but I'm almost positive that it won't outgun Snort. Or, you can do a bake-off between the two and pick what is better for your organization.
 
1 members found this post helpful.
  


Reply

Tags
ids, snort


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
1-snort Vs ntop-- 2- snort perfstat.exec PoleStar Linux - Newbie 1 09-06-2010 01:52 PM
[snort] Understanding Snort Rules Fracker Linux - Security 3 04-13-2009 09:34 AM
[HELP]SNORT PROBLEMS(IDS)-service snort start JayCool Linux - Software 5 03-15-2009 12:34 PM
Snort - no portscan and tcp alerts in snort av.dubey Linux - Software 6 07-11-2008 09:56 PM
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM


All times are GMT -5. The time now is 04:38 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration