Download presentation
Presentation is loading. Please wait.
Published byDarlene Stevens Modified over 9 years ago
1
7200 Samsung Confidential & Proprietary Information Copyright 2006, All Rights Reserved. -0/4- OfficeServ 7200 Enterprise IP Solutions - Data Server – IDS Rule Update Mar, 2006 OfficeServ Lab1 Samsung Electronics Co., Ltd.
2
7200 Samsung Confidential & Proprietary Information Copyright 2006, All Rights Reserved. -1/4- IDS functions Real-time detection and response to network based attacks –backdoor, DoS, DDoS, anomalous network access, etc. Using web management Support almost all kinds of protocol used in Internet Intrusion detection according to risk level –High, medium, low Correspond to intrusion detection –Log audit –IP blocking as linked with firewall Report to admin using e-mail about detected attacks –5 categories : Intrusion Type, Source IP, Destination IP, Port, Port scan Rule update
3
7200 Samsung Confidential & Proprietary Information Copyright 2006, All Rights Reserved. -2/4- IDS Rule Update Sourcefire VRT Certified Rules –Official rules of snort.org(www.snort.org)www.snort.org –Three ways to obtain these rules: Subscribers (a charge) –Online web subscriber –Receive real-time rules updates as they are available Registered users (Free) –Online web subscriber –Can access rule updates 5days after release to subscription users Unregistered users (Free) –Receive a static ruleset at the time of each major Snort Release –CANNOT use for WIM (limited to commercial use!)
4
7200 Samsung Confidential & Proprietary Information Copyright 2006, All Rights Reserved. -3/4- IDS Rule Update Open Community Rulesets –Submitted by members of the open source community –Release to users without basic tests not to ensure that new rules will not break Snort –Distributed under the GPL –Freely available to all open source Snort users
5
7200 Samsung Confidential & Proprietary Information Copyright 2006, All Rights Reserved. -4/4- Rule Update 1. If you click [Rule Config] from the left menu, you can update a ruleset. To update a ruleset click ‘browse’ button and select the desired rule file on your PC. WIM v1.21 IDS spec
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.