LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-24-2003, 03:36 PM   #1
mikmok
LQ Newbie
 
Registered: Dec 2003
Posts: 28

Rep: Reputation: 15
Snort performance


Hi all,
i'm trying snort with guardian.
I'm wondering how good this two programs can be togheter to protect my fw.
I have this doubt, excuse me if i didn't read all the snort documentation yet, because i can't realize how fast can be snort in detecting bad trafic expecially on a busy gw.
During the last our, i saw the guardian do his job in blocking the trafic from a suspicoius server/ip that was sending me a virus but only after that the connection was already closed.

The bad email with the virus has been delivered and after the end of the connection the snort/guardian has detected and put down a drop rule.

Do i miss something?
Do i need more computing power?
Does the snort do some kind of buffering and does it analyze the packets?
I suppose that expecially on busy gw and with a lot of packets per second this is the only way it can work. Am' i right?

Wich other tools like snort + guardian are available to analyze and block suspicious ip and from one of you reading this post already tested with success?.

Can snort detect p2p traffic made from clients that access the internet through a proxy like kadza ? How can i avoid and control that kind of traffic ?

thank you and merry Christmas to everybody.

Mik
 
Old 01-03-2004, 05:38 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
because i can't realize how fast can be snort in detecting bad trafic expecially on a busy gw.
Snort propaganda sez something about near-flawless detection on Gigabyte links, so.


During the last our, i saw the guardian do his job in blocking the trafic from a suspicoius server/ip that was sending me a virus but only after that the connection was already closed.
Detection isn't the same as blocking. I never did test Guardian for it's speed, but since it's a perl script I'm sure the interval it reads the log is tweakable.


Do i need more computing power?
HW/SW specs of the box?


Does the snort do some kind of buffering and does it analyze the packets?
Buffering in general I don't know, packet buffering yes, but only for fragments, and log buffering is a syslog/disk thing I suppose. Yes it does analyse packets, that's what makes it preferable over "dumb" portscan alerters like portsentry.


Wich other tools like snort + guardian are available to analyze and block suspicious ip and from one of you reading this post already tested with success?.
Check out the LQ FAQ: Security references, theres a part on IDSes.


Can snort detect p2p traffic made from clients that access the internet through a proxy like kadza ?
It's not about port access, it's the signatures. KaZaA v2 is harder to stop because it scans for other accessable ports.


How can i avoid and control that kind of traffic ?
Have and enforce a policy that denies local(net) users to run P2P SW.


merry Christmas to everybody.
Merry Christmas to you too. Bit early this year :-]
 
Old 01-20-2004, 10:12 AM   #3
mikmok
LQ Newbie
 
Registered: Dec 2003
Posts: 28

Original Poster
Rep: Reputation: 15
Hi, i paste a reply that i've received from the snort-user mailing list
Mik,
A number of issues here see below:-

>Hi all,
>i'm trying snort with guardian.
>I'm wondering about the performance that i can obtain
>from them togheter to protect my fw.
>I have this doubt, excuse me if i didn't read ALL the
>snort documentation yet, because i can't realize how
>fast can be snort in detecting bad trafic expecially
>on a busy gw.
>During the last hour, i saw the guardian do his job in
>blocking the trafic from a suspicoius server/ip that
>was sending me a virus but only after that the
>connection was already closed.

This is to be expected, when I used guardian on average the first
one or two packets got through before guardian re-acted, if memory
serves me correctly it looks for new entries every second by which
time the first packet that caused the alert is long gone. guardian
and iptables/ipchains or whatever then takes time to put the block in
place. Then no more subsequent attacks until guardian opens things
again. I used to use two days for the drop duration.

>The bad email with the virus has been delivered and
>after the end of the connection the snort/guardian has
>detected and put down a drop rule.

Personally with e-mail I don't touch this at the firewall level
but sort all the problems in the e-mail server and strip out
the viruses and do the spam filtering before passing it over to
the user accounts.

>Do i miss something?
>Do i need more computing power? i'm using a P3 with
>256 Mb ram.
>Does the snort do some kind of buffering and does it
>analyze the packets after a while?
>I suppose that expecially on busy gw and with a lot of
>packets per second this is the only way it can work.
>Am i right?

>Wich other tools like snort + guardian are available
>to analyze and block suspicious ip and from one of you
>reading this post already tested with success?.

I like snort_inline but it assumes you have an iptables based
firewall and as with guardian you have to eliminate
false positives from your selected rules otherwise valid
traffic gets dropped.

>Can snort detect p2p traffic made from clients that
>access the internet through a proxy like kadza ? How
>can i avoid and control that kind of traffic ?

>Tahnk you very much


>Mik

Hope the above helps
Brian.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM
Snort help Atrocity Slackware 9 05-24-2005 11:17 AM
Snort! lub0 Linux - Security 3 10-28-2003 01:54 PM
snort snort.conf help crealkiller175 Linux - Software 1 03-08-2003 05:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration