LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-26-2009, 09:51 AM   #1
Jim Bengtson
Member
 
Registered: Feb 2009
Location: Iowa
Distribution: Ubuntu 9.10
Posts: 164

Rep: Reputation: 38
EmergingThreats.Net


I ran across this site today, which looks very interesting. Has anyone heard of them before? Are they for real?

Quote:
About Emerging Threats
http://www.emergingthreats.net/index...inmenu-43.html

Emerging Threats is an open source community project. Through the support of our community we are able to produce the fastest moving and most diverse Snort Signature set and firewall rules available. Other related projects find a home here as well. Matt Jonkman manages this project.

Our content is free to use by any user or organization, commercial or private. We only ask that when you detect new threats in your environment or write new rules suitable for public release that you share that intelligence with the community at large. We update these rulesets as new information surfaces (usually several times a day 7 days a week) and highly recommend you update at least twice a week to stay up to date. Daily is your best bet.

Emerging Threats has been in operation under several names for over 5 years. We were formed originally as Bleeding Snort, but had to remove Snort from our name several years later when Sourcefire went public. We then became Bleeding Threats. That project had to be abandoned and is defunct unfortunately because of some possible license conflicts that appeared to be arising, so the entire ruleset was moved here, to Emerging Threats. In 2008 we received grant funding from the Army Research Office and the National Science Foundation to continue this project and research.
 
Old 10-26-2009, 09:56 AM   #2
MS3FGX
LQ Guru
 
Registered: Jan 2004
Location: NJ, USA
Distribution: Slackware, Debian
Posts: 5,852

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
Can't say I have any experience with them personally, but it looks interesting. Would like to see if anyone else has dealt with them in the past.
 
Old 10-26-2009, 11:30 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Quote:
Originally Posted by Jim Bengtson View Post
Has anyone heard of them before?
Yes. Been using their rules since they were called Bleeding Snort.


Quote:
Originally Posted by Jim Bengtson View Post
Are they for real?
Definately are. The obvious problem with Snort becoming Sourcefire was that paying customers gained instant rule access while non-paying users (who actually may have even helped Snort by developing and modifying rules and promoting the SW) were forced to wait a period. Emerging Threats rules are free and updated regularly.
 
Old 10-27-2009, 08:18 AM   #4
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by unSpawn View Post
Definately are. The obvious problem with Snort becoming Sourcefire was that paying customers gained instant rule access while non-paying users (who actually may have even helped Snort by developing and modifying rules and promoting the SW) were forced to wait a period. Emerging Threats rules are free and updated regularly.
I believe when Sourcefire releases new/revised rules, they initially give them to their subscribed customers, then release them to the the non-subscribed a week later.

I'm pretty sure you're aware of this (and I'm gonna summarize, so those who may poke holes later, just be aware that I'm trying to avoid a long and winded account of things), but the word is that Sourcefire was concerned that there were a lot of corporate entities that were using their rules and not contributing to them, to the extent that some were actually making money off of their rules. They wanted to prevent abuse of their good nature, I believe. Not that I agree or not agree.
 
Old 10-27-2009, 11:43 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Quote:
Originally Posted by unixfool View Post
They wanted to prevent abuse of their good nature, I believe.
Sounds reasonable. And compared with how some commercial vendors try to protect their market share they're still very lenient.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ava.net.ProtocolException: Already connected at gnu.java.net.protocol.http.HTTPURL trfunite Linux - Newbie 0 07-11-2008 06:04 AM
Linux/BSD VPN software for net-to-net with DynDNS at both ends? jantman Linux - Security 5 03-10-2008 12:20 PM
Lost ability to net-surf with toast.net dsl under openSUSE 10.3 DeekBeek Linux - Networking 5 02-10-2008 12:26 PM
LXer: How the Net was Lost - the real story behind Net Neutrality LXer Syndicated Linux News 0 06-20-2006 09:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration