Skip to Content
Managing Security with Snort & IDS Tools
book

Managing Security with Snort & IDS Tools

by Kerry J. Cox, Christopher Gerg
August 2004
Intermediate to advanced
288 pages
8h 30m
English
O'Reilly Media, Inc.
Content preview from Managing Security with Snort & IDS Tools

Chapter 6. Deploying Snort

Deploying an NIDS presents an administrator with some real challenges (apart from attempting to find a rational explanation for management on the return on investment for a security project). Installing and getting Snort up and running is just the beginning. You need to figure out what you want to watch, how you can watch it, and how to get meaningful information out of your effort.

Many of the obstacles to your NIDS deployment efforts are not technical at all. You might have to convince management that intrusion detection has value on par with the dollars and labor involved. Another, sometimes unforeseen issue is that an organization may have separate departments for network, server, and security administration—and communication between the groups may be poor.

Snort makes meeting these challenges a bit easier. Snort is free and will run on relatively low-cost hardware (it’s unreal how inexpensive memory and disk have become!). The initial installation and configuration of Snort is fairly straightforward, and you can use my experiences and advice in this book (and the available support of the open source community surrounding Snort) to aid in the ongoing maintenance and administration of your IDS installation. While Snort won’t magically get your different departments talking to one another, Snort sits as a passive listener on the network, needing little cooperation with the other departments to get installed and running. Once you call the server guys with ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Snort Intrusion Detection and Prevention Toolkit

Snort Intrusion Detection and Prevention Toolkit

Brian Caswell, Jay Beale, Andrew Baker

Publisher Resources

ISBN: 0596006616Errata Page