LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 08-26-2012, 01:45 PM   #1
baronobeefdip
Senior Member
 
Registered: Jul 2009
Distribution: Debian Squeeze
Posts: 1,267

Rep: Reputation: 32
Are there any recently published books on snort


I am taking a class on Firewalls and Intrusion Detection System and so far we have a book that we can reference for firewalls (IPTables) but we don't have a book that we can reference for SNORT. All of the books that I have been seeing were published all the way back in 2004, I am assuming that there has been many changes in snort since then (unless these changes don't seem relevant enough to where a person who is starting out with IDS systems couldn't understand the way the recent version works, in other words will it be to where the way the system is configured the same between the recent version and the aging reference book)

The only books that I have been seeing are the O'Reilly book and another from an unknown publisher (All I can say is that the pig mascot is on the cover) I have heard some good things about the o'reilly version but I want to known that if it has an explanation about the snort program and other IDS systems and does it show you how to make different rulesets for different types of attacks.
If not then do you have any suggestions (If so if you can provide a link to the paper back version on amazon that would be nice)
 
Old 08-26-2012, 05:26 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by baronobeefdip View Post
If not then do you have any suggestions
Here's what Joel Esler says:

Quote:
(..) if I could, I'd pull the book from every shelf, (..) It covered Snort version 2.6 and was written during Snort 2.5, if that tells you the age of the book. There were several chapters (..) that are just plain wrong.
(http://seclists.org/snort/2012/q1/175)

Quote:
It is our opinion that the Snort Reference Manual, and things that I have planned for the future will make a more effective documentation method than any static book would be.
(http://seclists.org/snort/2012/q1/180)

...so according to (one of) the SourceFire people you best start with the Snort Manual (http://manual.snort.org/). From the looks of it "Writing Snort Rules" now is part of it as chapter 3 too. Rules are easy to start with but when you have questions don't forget to tap into the power of mailing list (archives) like http://www.snort.org/community/mailing-lists/ and http://lists.emergingthreats.net/mailman/listinfo/ and various web logs. Yes, not having a dead tree around may suck major but until you're at the proficiency level where shelling out cash for a course becomes reality it is the cheapest, and apparently most up to date, option.
 
Old 08-26-2012, 05:37 PM   #3
baronobeefdip
Senior Member
 
Registered: Jul 2009
Distribution: Debian Squeeze
Posts: 1,267

Original Poster
Rep: Reputation: 32
Quote:
Originally Posted by unSpawn View Post
Here's what Joel Esler says:


(http://seclists.org/snort/2012/q1/175)


(http://seclists.org/snort/2012/q1/180)

...so according to (one of) the SourceFire people you best start with the Snort Manual (http://manual.snort.org/). From the looks of it "Writing Snort Rules" now is part of it as chapter 3 too. Rules are easy to start with but when you have questions don't forget to tap into the power of mailing list (archives) like http://www.snort.org/community/mailing-lists/ and http://lists.emergingthreats.net/mailman/listinfo/ and various web logs. Yes, not having a dead tree around may suck major but until you're at the proficiency level where shelling out cash for a course becomes reality it is the cheapest, and apparently most up to date, option.
I am aware of the documentation on the snort website I am looking for a paperback copy of it since not everyone has a tablet and/or laptop (in fact they aren't even allowed in the class) and I don't want to make it available on the screen of the computer since not everyone will be willing to buy the digital copy as opposed to the paperback one. I need a paperback book about snort and IDS tools.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
1-snort Vs ntop-- 2- snort perfstat.exec PoleStar Linux - Newbie 1 09-06-2010 01:52 PM
[SOLVED] Recommended Snort Books helptonewbie Linux - Security 5 07-27-2010 08:10 AM
[HELP]SNORT PROBLEMS(IDS)-service snort start JayCool Linux - Software 5 03-15-2009 12:34 PM
Snort - no portscan and tcp alerts in snort av.dubey Linux - Software 6 07-11-2008 09:56 PM
snort rules to vulns not yet published zuessh Linux - Security 1 02-12-2004 02:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 05:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration