Snort (software)
Snort is a GPL-licensed open source network intrusion detection system. Originally it is written by Martin Roesch, nowadays owned and operated by Sourcefire. Check Point aquired Sourcefire in 2005. Commercial versions with integrated hardware and support services are sold by Sourcefire. Snort is capable of performing real-time traffic analysis and packet logging on IP networks. It can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more. The system can be used for intrusion prevention purposes too. Snort can also be combined with other open source projects such as SnortSnarf, ACID, sguil, and the "Basic Analysis and Security Engine" (BASE) to provide a visual representation of intrusion data.
External links
- Snort homepage
- The Bleeding Edge of Snort - Community maintained Snort rulesets
- TurboSnortRules.org - Test the performance of your Snort rules
- Basic Analysis and Security Engine - The Web-based GUI frontend for Snort