My Account Log in

1 option

IDS and IPS with Snort 3 : Get up and Running with Snort 3 and Discover Effective Solutions to Your Security Issues / Ashley Thomas.

O'Reilly Online Learning: Academic/Public Library Edition Available online

View online
Format:
Book
Author/Creator:
Thomas, Ashley, author.
Language:
English
Subjects (All):
Snort (Computer file).
Computer networks--Security measures.
Computer networks.
Computers--Access control.
Computers.
Computer security.
Physical Description:
1 online resource (256 pages)
Edition:
First edition.
Place of Publication:
Birmingham, England : Packt Publishing Ltd., [2024]
Biography/History:
Thomas Ashley: Ashley Thomas is a security researcher at Dell SecureWorks and a member of the Counter Threat Unit team. Before this role, he was instrumental in building the iSensor, a proprietary network intrusion prevention system. Ashley has a master's in computer networking from North Carolina State University, and he also holds several other certifications, including CISSP, GCIA, GREM, GCLD, and GWEB. He has authored several papers on intrusion detection and holds several patents in this field.
Summary:
Learn the essentials of Snort 3.0, including installation, configuration, system architecture, and tuning to develop effective intrusion detection and prevention solutions with this easy-to-follow guide Key Features Get to grips with the fundamentals of IDS/IPS and its role in network defense Explore the architecture and key components of Snort 3 and get the most out of them Migrate from Snort 2 to Snort 3 while seamlessly transferring configurations and signatures Purchase of the print or Kindle book includes a free PDF eBook Book Description Snort, an open source intrusion detection and prevention system (IDS/IPS), capable of real-time traffic analysis and packet logging, is regarded as the gold standard in IDS and IPS. The new version, Snort 3, is a major upgrade to the Snort IDS/IPS, featuring a new design and enhanced detection functionality, resulting in higher efficacy and improved performance, scalability, usability, and extensibility. Snort 3 is the latest version of Snort, with the current version at the time of writing being Snort v3.3.3. This book will help you understand the fundamentals of packet inspection in Snort and familiarize you with the various components of Snort. The chapters take you through the installation and configuration of Snort, focusing on helping you fine-tune your installation to optimize Snort performance. You'll get to grips with creating and modifying Snort rules, fine-tuning specific modules, deploying and configuring, as well as troubleshooting Snort. The examples in this book enable network administrators to understand the real-world application of Snort, while familiarizing them with the functionality and configuration aspects. By the end of this book, you'll be well-equipped to leverage Snort to improve the security posture of even the largest and most complex networks. What you will learn Understand the key changes in Snort 3 and troubleshoot common Snort 3 issues Explore the landscape of open source IDS/IPS solutions Write new Snort 3 signatures based on new threats and translate existing Snort 2 signatures to Snort 3 Write and optimize Snort 3 rules to detect and prevent a wide variety of threats Leverage OpenAppID for application detection and control Optimize Snort 3 for ideal detection rate, performance, and resource constraints Who this book is for This book is for network administrators, security administrators, security consultants, and other security professionals. Those using other IDSs will also gain from this book as it covers the basic inner workings of any IDS. Although there are no prerequisites, basic familiarity with Linux systems and knowledge of basic network packet analysis will be very helpful.
Contents:
Cover
Title Page
Copyright and Credits
Contributors
Table of Contents
Preface
Part 1: The Background
Chapter 1: Introduction to Intrusion Detection and Prevention
The need for information security
Defense-in-depth strategy
Firewalls (network and host layers)
Intrusion detection and prevention systems (network and host layers)
Endpoint detection and response (host layer)
Web application firewalls (network and host layers)
Mail security gateway (network)
Log management and monitoring (network and host)
The role of network IDS and IPS
Types of intrusion detection
Signature-based intrusion detection
Anomaly-based intrusion detection
Hybrid intrusion detection
The state of the art in IDS/IPS
Stateful analysis
Fast packet acquisition
Parallel processing
Pattern matching
Extending rule language
App and protocol identification
File analysis
IDS/IPS metrics
Detection accuracy
Performance-related IDS/IPS metrics
IDS/IPS evaluation and comparison
Evasions and attacks
IDS/IPS evasions
Attacks against the IDS/IPS
Summary
Chapter 2: The History and Evolution of Snort
The beginning of Snort
Snort 1 - key features and limitations
Snort 2 - key features, improvements, and limitations
Snort 2.9
The need for Snort 3
Part 2: Snort 3 - The New Horizon
Chapter 3: Snort 3 - System Architecture and Functionality
Design goals
High performance
Pluggable modular architecture
Configurability and customizability
Efficiency
Key components
DAQ module
Codecs
Inspectors
Detection or rule engine
Configuration module
Alerting and logging module
Snort 3 system architecture
Multithreading
Packet analysis flow within each Snort thread
Chapter 4: Installing Snort 3.
Choosing an OS for installing Snort 3
Snort 3 installation process
Preparing the system
Installing dependencies
Installing Snort 3
Installing Snort 3 on CentOS
Installing build tools
Installing Snort 3 on Kali (Debian)
Chapter 5: Configuring Snort 3
Configuring Snort 3 - how?
Command-line arguments
Configuration files
Configuring Snort 3 - what?
Configuring defaults
Configuring inspection
Configuring bindings
Configuring performance
Configuring detection
Configuring filters
Configuring output
Configuring your environment
HOME_NET
EXTERNAL_NET
HTTP_PORTS
The stream_tcp inspector
Optimal configuration and tuning
Managing multiple policies and configurations
Part 3: Snort 3 Packet Analysis
Chapter 6: Data Acquisition
The functionality of the DAQ layer
The performance of the DAQ Layer
Factors affecting packet capture performance
The consequence of packet capture performance degradation
Packet capture in Snort
Before DAQ
The DAQ module - introduced in Snort 2.9
The Snort 3 implementation of the DAQ layer
The DAQ library API
DAQ modules
Configuring DAQ
Chapter 7: Packet Decoding
OSI layering and packet structure
Data encapsulation and decapsulation
The role of packet decoding (Codecs)
Packet decoding in Snort 3
EthCodec - a layer 2 codec
IPv4Codec - a layer 3 codec
TcpCodec - a layer 4 codec
Code structure and other codecs
Chapter 8: Inspectors
The role of inspectors
Types of inspectors
Network inspectors
Service inspectors
Stream inspectors
Snort 3 inspectors
Service inspectors.
Stream inspectors
Wizard and binder inspectors
Chapter 9: Stream Inspectors
Relevant protocols for the stream inspector
IP
ICMP
TCP
UDP
Flow
The stream inspectors
stream_ip
stream_udp
stream_icmp
stream_tcp
stream_base
Chapter 10: HTTP Inspector
Basics of HTTP
HTTP request
HTTP response
HTTP/2
HTTP inspector
HTTP buffers
HTTP/2 inspector
HTTP inspector configuration
Chapter 11: DCE/RPC Inspectors
A DCE/RPC overview
Connectionless versus connection-oriented DCE/RPC
DCE/RPC inspectors
DCE/RPC rule options
Exercise
Chapter 12: IP Reputation
Background
IP address as an entity - use of blocklists
Challenges
History of IP blocking in Snort
Configuration of the IP reputation inspector module
Functionality of the IP reputation inspector
Data structure for storing IP reputation scores
IP reputation inspector - alerts and pegs
Part 4: Rules and Alerting
Chapter 13: Rules
Snort rule - the structure
Service rule
File rule
File identification rule
Rule header
Traditional rule header
Rule options
General rule options
Payload options
Non-payload options
Recommendations for writing good rules
Using fast_pattern wisely
Using the inspection buffers for rule matching
Defining the right service or protocol
Chapter 14: Alert Subsystem
Post-inspection processing
Event generation
Event thresholding
Applying a rule action to a packet
Logging the alert
Alert formats
CSV format
Unified2 format
Alert Fast format
Alert Full format
JSON format
Chapter 15: OpenAppID
The OpenAppID feature
Design and architecture
Detectors
The inspector
The rules
Summary.
Chapter 16: Miscellaneous Topics on Snort 3
Snort 2 to Snort 3 migration
Migrating the rules
Migrating configurations
Troubleshooting Snort 3
Why is the Snort rule for XYZ not alerting?
Snort is crashing!
Help! Got support?
Index
Other Books You May Enjoy.
Notes:
Includes index.
Description based on publisher supplied metadata and other sources.
Description based on print version record.
ISBN:
9781800569423
1800569424
OCLC:
1455105279

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account