Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security

Compiling Snort Rules 10

Sergei Egorov writes "Good people at Fidelis Security Systems developed SNORTRAN, an optimizing compiler for Snort rules. By combining several compilation techniques, SNORTRAN is able to translate a set of Snort rules into a high-performance intrusion detection engine. SNORTRAN-generated engines are 4 to 6 times faster than Snort's own detection engine; this translates into 3 to 5 overall speedup factor for a complete Snort system (benchmarks are here)."
This discussion has been archived. No new comments can be posted.

Compiling Snort Rules

Comments Filter:
  • by Krelnik ( 69751 ) <timfarley@@@mindspring...com> on Monday October 07, 2002 @03:42PM (#4405678) Homepage Journal
    FYI, they are not the first to run Snort rules faster than Snort does. RealSecure 7.0 [iss.net] by ISS already does this. I believe they use a similar technique internally, although I have no direct knowledge of it. RealSecure can also run rings around Snort performance-wise on off-the-shelf hardware, particularly with certain types of attacks going on.

    However, as explained in this white paper [iss.net] you might not even want to try to run Snort rules in RealSecure, because in many cases its own signatures are much more accurate. That's because RealSecure actually does protocol analysis, while Snort just matches patterns. See the paper for details.

    Full disclosure: I used to work at ISS [iss.net] and still own a bunch of stock in it. However I wouldn't post this for any of their products (some of them suck). RealSecure is one of their good ones.

  • Heh heh (Score:5, Funny)

    by greenhide ( 597777 ) <`moc.ylkeewellivc' `ta' `todhsalsnadroj'> on Monday October 07, 2002 @04:23PM (#4406018)
    Yeah--yeah--compiling snort rules.

    Huh huh.
  • So how does it compare with prelude and portsentry?
    My understanding is that snort is only good at single networks, anything more than that you will want prelude. Any truth to this? ***this was on a prelude irc channel*** What's the real deal slasdot-istas?

Algebraic symbols are used when you do not know what you are talking about. -- Philippe Schnoebelen

Working...