Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Anyone familiar with SNORT..... alert file

Status
Not open for further replies.

iam3

Programmer
Oct 30, 2001
6
NO
I am referring to IDS called Snort. In Snort there is a file called alert, which holds chronological summary( a BIG one) of possible security problems. Do you think that all of these alerts correspond to real attack?
 
No, SNORT (and all IDS's) will have MANY "false possitives".

The job of a security analyst is to go thru the logs proactively (and regularly <G>) looking for anomalies that point to security events.

It takes some time to fine tune an IDS to ignore the false positives but not miss an actuall security event, but by going thru the logs and looking at what is being reported, you will begin to learn the difference and be in a better position to manage your IDS :)

---
John Hoke<br>
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top