IDS mailing list archives

Re: network segment which NIDS can detect?


From: Thiago Mello <indio () underprotection com br>
Date: 18 Jun 2003 11:57:49 -0300

Hi,

In Sans website have a article explaining how to use Snort IDS in a
distributed enviroment, I did not implment it, soh I can't tell my
opnion. If you implement this solution you could tell us abou your
experience.

http://www.sans.org/rr/paper.php?id=352

Thiago Mello

On Sun, 2003-06-15 at 22:10, SB CH wrote:
Hello, all.

I installed snort NIDS at my switch and I confirmed that snort can detect 
some other servers were attacked. As I know, NIDS can detect some other 
attacks in the range of network segment.
Then what is a "same network segment" in the switch?
I can detect some attacks to A server, but B isn't which use same switch 
connected.

I would like to setup Distrubuted NIDS(D-NIDS) using snort and I have 
operated some switches.
Where can I setup snort NIDS to use D-NIDS?

Thanks in advance.

_________________________________________________________________



-------------------------------------------------------------------------------
Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
world's premier technical IT security event! 10 tracks, 15 training sessions, 
1,800 delegates from 30 nations including all of the top experts, from CSO's to 
"underground" security specialists.  See for yourself what the buzz is about!  
Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
-------------------------------------------------------------------------------


Current thread: