Skip to main content

Securing a Windows Snort Sensor for Hostile Environments

Snort is an open-source Network Intrusion Detection System (NIDS). Originally written for UNIX, it has since been ported to the Windows platform. While Snort undoubtedly runs faster and with less packet loss on a UNIX host, many organizations lack the requisite skill sets to deploy and maintain a UNIX host within their environment. For these organizations, Snort on Windows 2000 provides a low-cost, high-quality NIDS. Deploying Snort on Windows can be a convoluted process. Michael Steele of Silicon Defense has simplified the installation with his excellent paper, 'Snort Installation Manual - Snort MySQL Acid & IIS - Windows NT4 Server2000 & XP (All Versions)1.' His paper lays out a step-by-step procedure for the complicated build process. But it does not address the security of the Snort sensor. Indeed a sensor built solely to his specifications will not survive on any but the most trusted of network segments. This white paper documents how to secure a Windows' Snort sensor for deployment into extremely hostile environments.

1074 (PDF, 1.97MB)

3 Jun 2003
ByMichael Wunsch
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Malware Function-based encryption technique

Research Paper

Recent malware often uses techniques to evade detection by cybersecurity products. One of the...

  • 22 Jun 2022

Detecting Unauthorized Behavior From Legitimate Accounts

Research Paper

Incident Responders face an almost insurmountable amount of log events, and the move to the Cloud...

  • 22 Jun 2022

Recover an RSA Private Key from a TLS v1.2 session

Research Paper

Cyberattacks happen every day.Most organizations have administrative and technical controls...

  • 22 Jun 2022

Cyber Guardian Exercise: A Case Study in Brazil to Address Challenges in Cybersecurity and Protect Critical Infrastructure

Research Paper

Discussions of cybersecurity, in particular those associated with critical infrastructure (CI),...

  • 22 Feb 2022

Recommendations for small/medium-sized businesses enabling incident response

Research Paper

Security incidents are inevitable. While large businesses can afford security teams to prepare and...

  • 17 Jan 2022

Black-Box Fuzzing for Android Native Libraries

Research Paper

Many Android application developers are adopting C\C++ native language development in their Android...

  • 12 Jan 2022

Machine Learning Techniques for Intrusion Detection

Research Paper

This paper aims to equip intrusion analysts with the basic techniques needed to apply machine...

  • 9 Jun 2021

Detecting DLL Search Order Hijacking: How using a purple team approach can help create better defensive techniques and a more tactical SIEM

Research Paper

Many SIEM analysts will recognize the feeling of being overwhelmed with security logs and alerts,...

  • 4 May 2020

Corporate Information Governance with Business Wisdom

Research Paper

Whether a secret ingredient used for a lemonade stand across the street or the business strategies...

  • 4 May 2020

Automated Detection and Disinfection of Ransomware Attacks using Roadblock Software

Research Paper

We often hear about ransomware locking data and demanding the ransom. Ransomware is a kind of...

  • 18 Mar 2020

Assisted Security Investigations Using Cognitive Computing

Research Paper

The purpose of this research is to illustrate the application of cognitive computing and machine...

  • 3 Dec 2019

Leveraging the PE Rich Header for Static Malware Detection and Linking

Research Paper

An ever-increasing number of malware samples are identified and assessed daily. Malware researchers...

  • 1 Jul 2019

Analysis of a Multi-Architecture SSH Linux Backdoor

Research Paper

A key aspect in any intrusion is to attempt to gain persistence on the compromised system. Threat...

  • 17 Jun 2019

Unpacking and Decrypting FlawedAmmyy

Research Paper

Malware authors commonly utilize packers (Roccia, 2017) as a method of concealing functionality and...

  • 22 Apr 2019

Continuous Security Monitoring in non-Active Directory Environments

Research Paper

Active Directory-centric monitoring techniques, tools, and methodologies have dominated information...

  • 20 Feb 2019

Intrusion Prevention System Signature Management Theory

Research Paper

The intrusion prevention system (IPS) serves as one of the critical components for a...

  • 5 Feb 2019

SDN Southbound Threats

Research Paper

SDN (Software-Defined Networks) technologies are based on three pillars: decoupling control and...

  • 20 Nov 2018

Processing experimental protocols against IDS

Research Paper

Experimental protocols such as TCP Fastopen, QUIC, and Multipath TCP are not uncommon on...

  • 10 Aug 2018

Extracting Timely Sign-in Data from Office 365 Logs

Research Paper

Office 365 is quickly becoming a repository of valuable organizational information, including data...

  • 22 May 2018

Automated Detection and Analysis using Mathematical Calculations

Research Paper

A compromised system usually shows some form of anomalous behaviour. Examples include new processes,...

  • 17 May 2018

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.