APLawrence.com -  Resources for Unix and Linux Systems, Bloggers and the self-employed

Some material is very old and may be incorrect today

© May 2005 Tony Lawrence

Snort Cookbook



Snort is deceptively simple to get started with. On many platforms, you don't even have to compile anything; you can get current binaries for Linux, Mac OS X and even Windows. Nor do many users have to bother with any configuration: the defaults are often perfectly suitable.

This book presents recipes for those who want to do more. I liked that it gave space to Windows, Linux and Mac issues, but I did find this a bit jumbled and disorganized. To some extent, that's the nature of "cookbook" style books, and it's not that there was no attempt at gathering these into major chapter sections like Installation, Logging, etc. I just felt it could have been done better.

I was also a bit disappointed with the coverage of rules in general. Rules are the heart of Snort and this book doesn't do a very good job explaining them. Snort rules aren't particularly difficult (see Snort Users Manual for a good intro), and the authors probably just assumed that you are already at least somewhat familiar with them.

On the other hand, there are a lot of useful tips here. I was not previously aware of the "resp:" mechanism which allows you to close of a session that Snort has identified. None of the rules included with Snort use that, and I must not have gotten that far in the docs, so this was news to me. I also was unaware of Oinkmaster news for rule updates; the Snort site doesn't mention that. There was more, but these two stand out in my memory.

If you are using Snort, this book might help you get more use out of it.

Amazon Order (or just read more about) Snort Cookbook  from Amazon.com

If you found something useful today, please consider a small donation.



Got something to add? Send me email.





(OLDER)    <- More Stuff -> (NEWER)    (NEWEST)   

Printer Friendly Version

->
-> Snort Cookbook


Inexpensive and informative Apple related e-books:

Take Control of Pages

Photos: A Take Control Crash Course

iOS 8: A Take Control Crash Course

Take Control of Numbers

Are Your Bits Flipped?





More Articles by © Tony Lawrence





Printer Friendly Version

Have you tried Searching this site?

This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more.

Contact us


Printer Friendly Version





Try not to become a man of success, but rather try to become a man of value. (Albert Einstein)




Linux posts

Troubleshooting posts


This post tagged:

Security



Unix/Linux Consultants

Skills Tests

Unix/Linux Book Reviews

My Unix/Linux Troubleshooting Book

This site runs on Linode