[Snort-users] Security Audit

This is a discussion on [Snort-users] Security Audit within the Snort forums, part of the System Security and Security Related category; Greetings all, First off, thank you, to everyone who has dedicated their time and talents to building snort. Your efforts ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 12-11-2004
Steven Crandell
 
Posts: n/a
Default [Snort-users] Security Audit

Greetings all,

First off, thank you, to everyone who has dedicated their time and
talents to building snort. Your efforts are, by any measure, hugely
successful and greatly appreciated.

My situation in short:
Tomorrow my company will endure our quarterly security audit. The
president of the company isn't terribly worried about our IDS most of
the time, however when the audits occur, he's intensely interested in
making sure that our IDS sees every bit of traffic involved in the
audit.

The 3rd party performing the audit has, once in the past, managed to
perform their audit without being detected by our IDS. I would like
to make sure this doesn't happen again.
So, can anyone recommend any tips to making sure that we detect scans
(even really slow, stealth scans) from behind a firewall that only
permits traffic across ports 80 and 22?

Given that I have the source ip from which the audit will originate, I
can and certainly will, write a simple rule to capture and log all
traffic from the IP in question. This is, of course, not possible in
the process of day-to-day detection.

I wonder if any of you have any words of wisdom to help me overcome this issue.

It may be worth noting that:
-I'm dealing with a class C network
-I am using the flow-portscan preprocessor already

Thank you in advance.

Very best regards,

--
Steven Crandell
steven.crandell@gmail.com

"Getting an ethics lesson from the guy who cracked
makelovenotspam.com.........priceless"


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://productguide.itmanagersjournal.com/
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:57 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0