header image
Meetings
The next meeting of the NYC Snort User Group is under development. If you are interesting in presenting or speaking please contact mo@ciphertechs.com
Twitter
You can now follow this group on Twitter at twitter.com/nycsnort
Calendar
September 2010
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
27282930EC
  • No events scheduled
Archives
Poll

What OS are you running Snort IDS on?

View Results

Loading ... Loading ...
Tools
VRT Advisories
Project Razorback™ (formerly known as Near Real-Time Detection)
June 14th, 2010 under Articles, Sourcefire, Tools, White papers by jonbaer [ Comments: none ]

Near Real-Time Detection (Razorback) is the result of extensive research into detection of attacks hidden inside numerous layers of compression, obfuscation, and evasion techniques across multiple file formats. Razorback in its current form is a plugin to the Snort detection engine. Razorback addresses the issues with file format parsing by separating selected file types from transmitted data, which are then passed to additional detection engines either on local or distributed remote system(s). The intention is for the system to be extensible and not necessarily be a plugin for Snort.

screen-shot-2010-06-15-at-110538-am.png

Future development plans include providing Snort with automatic detection rule updates that an IPS deployment of Snort can use to protect the private network along with further enhancements aimed at data leak prevention. The system will also use templates to describe file types and a simple rule language to detect attacks.

Click here for code and presentation

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • Reddit
  • Spurl
  • Technorati
  • blogmarks
  • Blue Dot
  • NewsVine
  • Slashdot
  • StumbleUpon


Criteria for evaluating IDS / IPS
May 2nd, 2007 under White papers by michelangelo [ Comments: none ]

This paper provides readers with an excellent overview of the criteria that need to be followed to select and properly scale an IDS / IPS enterprise installation.

It ranks the criteria as Must Have, Should Have, and Good to Have so you can prioritize different vendors’ IDS features.

This paper is a MUST-HAVE prior to starting any IDS / IPS implementation project.

http://www.snort.org/docs/IDS_criteria.pdf

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • Reddit
  • Spurl
  • Technorati
  • blogmarks
  • Blue Dot
  • NewsVine
  • Slashdot
  • StumbleUpon


 

About NY-SUG
The New York Snort User Group currently meets on a monthly basis at CipherTechs in downtown New York City to openly discuss network security with a focus on the open source IDS Snort. If you are interested in joining us, please sign up to the mailing list.
New Posts
Twitter
Exploits
Bathroom repair cheaply.