Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 32 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow IDS / IPS software for Lab
EH-Net
May 26, 2013, 02:06:07 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: IDS / IPS software for Lab  (Read 13510 times)
0 Members and 1 Guest are viewing this topic.
delusion
Newbie
*
Offline Offline

Posts: 49



View Profile
« on: July 21, 2011, 07:54:00 AM »

Hi Guys  Grin

This isn't a hacking query of such although it is understanding security in order to defend against hackers.

So I've gained real world exposure monitoring IPS systems although I've never had the chance to implement one and I am a firm believer of understanding the guts of a system.

So my question to you is does anyone know of any good free IPS software which can be configured and tweaked and whatnot which are as robust as one used within an enterprise and runs on windows 7?

I am currently getting my head around Snort although a network manager told me its legacy.  Its seems like the only option in my eyes although I am still searching.

Any thoughts are welcome as ever!  Cool
Logged

You Cant Resolve Problems Whilst At WAR!
delusion
Newbie
*
Offline Offline

Posts: 49



View Profile
« Reply #1 on: July 21, 2011, 07:56:24 AM »

Just to mention if anyone has used any paid for versions which don't leave a detrimental mark on your wallet then I maybe inclined to part with a small amount of cash.
Logged

You Cant Resolve Problems Whilst At WAR!
celord
Guest
« Reply #2 on: July 21, 2011, 08:02:51 AM »

Hi, I am a newbe too, but I do not think Snort is legacy, I would keep the effort on that direction.
Logged
cd1zz
Recruiters
Hero Member
*
Offline Offline

Posts: 561


View Profile WWW
« Reply #3 on: July 21, 2011, 08:05:25 AM »

You can try Suricata http://www.openinfosecfoundation.org/index.php/download-suricata

It's built on top of SNORT but it's worth a look.
Logged

delusion
Newbie
*
Offline Offline

Posts: 49



View Profile
« Reply #4 on: July 21, 2011, 08:18:38 AM »

My argument against snort is that it just detects.  I'm sure its fit for purpose although i am looking for IPS implementation exposure.  Ideally.

cd1zz - Thanks will look into it now.
Logged

You Cant Resolve Problems Whilst At WAR!
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #5 on: July 21, 2011, 08:25:28 AM »

FYI Snort doesn't just detect it prevents as well. As a matter of fact, Snort can do whatever you want it to do since you create your own sigs and can assign it to perfom system commands based on triggers. In either event, you could also try HLBR although it hasn't been updated in a while

http://hlbr.sourceforge.net/
Logged

hell_razor
Jr. Member
**
Offline Offline

Posts: 90


View Profile
« Reply #6 on: July 21, 2011, 08:49:09 AM »

Check out Doug Burk's Security Onion.  It includes a couple of engines and a lot of GUIs.

And, btw, snort should not be considered legacy or obsolete yet...it does what it does very well.

hxxp://securityonion.blogspot.com/
« Last Edit: July 21, 2011, 11:03:36 AM by hell_razor » Logged

A+, Network+, Server+, CISSP, GSEC, GCIH, GPEN, GCIA, GISP, GCFW
delusion
Newbie
*
Offline Offline

Posts: 49



View Profile
« Reply #7 on: July 21, 2011, 09:24:58 AM »

Thanks Snort sounds like the best option then I will stick with that for now and perhaps experiment with other recommendations once Snort is fully functional.

Thanks for your thoughts.
Logged

You Cant Resolve Problems Whilst At WAR!
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #8 on: July 21, 2011, 09:45:55 AM »

For some smaller shops (aka - schools and other,) I've also been glancing over Untangle.

http://www.untangle.com/

Does use snort underneath, and has some other neat little utils and add-on's, both free and for $, for lesser-experienced setups.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
delusion
Newbie
*
Offline Offline

Posts: 49



View Profile
« Reply #9 on: July 21, 2011, 10:47:04 AM »

Good find  Shocked Thanks hayabusa!
Logged

You Cant Resolve Problems Whilst At WAR!
mambru
Jr. Member
**
Offline Offline

Posts: 98


View Profile
« Reply #10 on: July 21, 2011, 04:01:49 PM »

Quote
You can try Suricata http://www.openinfosecfoundation.org/index.php/download-suricata

It's built on top of SNORT but it's worth a look.

Suricata is NOT built on top of Snort. Suricata engine is completely written from 0, it supports the rules language from Snort, but it does not use any code from Snort.
Logged
cd1zz
Recruiters
Hero Member
*
Offline Offline

Posts: 561


View Profile WWW
« Reply #11 on: July 21, 2011, 04:04:50 PM »

@mambru is an active coder on the project......so he would know!!!!
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #12 on: July 21, 2011, 04:05:11 PM »

Quote
You can try Suricata http://www.openinfosecfoundation.org/index.php/download-suricata

It's built on top of SNORT but it's worth a look.

Suricata is NOT built on top of Snort. Suricata engine is completely written from 0, it supports the rules language from Snort, but it does not use any code from Snort.

++1
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.066 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.