Session 4: Introducing SnortSession Objectives
- Revisit and augment our understanding of various uses of IDSes.
- Introduce the IDS tool Snort, including its development history and current status.
- Understand the four primary system components of Snort and the function of each.
- Consider some of the factors that go into planning an IDS installation.
- Review the steps in the process for installing and configuring Snort (hopefully you have already worked through this process once).
- Discover some NIDS deployment architecture patterns for common Internet-facing network designs.
To Do List
Check your essay before you submit. See exactly what your professor sees.
See your AI and plagiarism results before your instructor does.Get the exact same report your professor uses. Trusted by 50,000+ students worldwide.
Tasks
- Read the session notes (below), including any embedded URL links.
Readings/OERs
- Snort Manual
http://manual-snort-org.s3-website-us-east-1.amazonaws.com/
- Intro to Snort
https://snort.org/documents/intro-to-snort
- Snort FAQ
https://www.snort.org/faq
Assignments
- Complete and submit your first homework assignment (described below) by the end of the session.
Homework Assignment #2
Both Session 2 and Session 3 addressed considerations and decision criteria for placing IDS within a network architecture. We will pick up this theme with our second homework assignment, which will be due at the end of session 5. Your assignment is to create a network “architecture” diagram representing your home network (presuming you have Internet access from home) and to indicate on the diagram where you might locate IDS sensors. You need not use a technical drawing tool such as Visio, nor do you need to find relevant clip art or other graphics for your diagram. Lines and boxes such as those you can produce in PowerPoint are sufficient. If drawing via computer is not feasible, I will accept a scanned image of a hand-drawn diagram as well. For those of you interested in creating technical diagrams but not interested in the expense of a professional program like Visio or MagicDraw, there is an open-source drawing program called Dia that offers many similar features and is suitable among other things for network diagrams. It is available for Windows and Linux platforms at http://www.gnome.org/projects/dia/.
Since the assignment asks you to use your own home network as a focus, and many home networks are quite understandably simple in design, it is acceptable and even encouraged for you to produce a diagram of what your home network might look like if you determined you had a need for components like dedicated IDS solutions. Your diagram should include the following elements at a minimum:
- Representation of your Internet connection (whether dial-up, cable modem, router, etc.)
- Computers connected to the network, as well as a designation of whether the connection type is wired or wireless (or both)
- Any other devices attached to the network
- The location and type of any IDS sensors you would place on the network
A brief text description of the diagram should also be included, particularly to explain your choices about IDS placements. Your homework assignment should be submitted via your Assignments folder. I will post a diagram of what I expect will seem to be a slightly more-complex-than-average home network environment for reference at the end of the session.
Session Notes
Preliminaries
This week we shift our focus from IDS in the abstract to take a close look at the Snort network-based IDS tool, as a preliminary step to working with this tool later in the course with some hands-on exercises. There have been a few books published on Snort, but none of the note in nearly ten years and the current version of Snort is nearly unrecognizable compared to prior versions described in available books. For this reason, we go straight to the source this week for our reading and rely on Sourcefire (Snort’s developer, now part of Cisco). Your emphasis should be to get a feel for the functional capabilities and intended purpose of Snort, being mindful of considerations introduced in prior sessions that factor into decision making about where to place IDS sensors in an environment, and about planning the implementation of an IDS product such as Snort.
The level of detail in the Snort Manual and some of the other materials available on snort.org varies widely. Reading a current copy of the Snort manual helps ensure that descriptions of preprocessors and other add-ons to the core detection engine are accurate and up to date, although it is quite difficult to get a comprehensive understanding of Snort and how its components work without consulting the documentation provided with the source code for the tool. This is not a course on programming or tool design, and there is no reason to expect that most students are familiar with or comfortable reading source code that is written in C (the primary programming language used for Snort). To understand the process of installing and configuring Snort you may find the instructions I have provided in the General Information module on installing Snort on Linux and Windows (or the HTML version of the same material). You don’t have to install snort on your machine for this course.
Introduction to Snort
We previously introduced Snort as the most common example of a signature-based network IDS, and Snort remains by far the most popular open-source NIDS. The Snort manual provides a good introduction to rules, syntax, and detection methods and to various means of conducting an effective analysis of information produced by the tool in production using output plugins. Please bear in mind that you can always refer to the Snort website at http://www.snort.org/ as an additional reference for things like rulesets, product documentation, and discussion threads on working with Snort. Students are encouraged, though not required, to register as users on Snort.org (there is no fee to register). Becoming a registered user gives you full access to Snort discussions in the forum area, and also allows you to download current Snort rulesets (the Virtual Lab environment, which has to be finalized well in advance of the start of each term, tends to lag slightly behind the most current version of Snort and associated rules, but the rules deployed on your virtual machine instances are appropriate for the version of Snort that is installed.
Review Questions
- What is Snort? What type of IDS is it? What are its three main functions?
- How do the four Snort program components work together to optimize the tool’s performance?
- What are some of the trade-offs that factor into implementing a Snort sensor?
- What operating systems does Snort support? Is there a “best” OS for Snort?
- What are some ways to use Snort to monitor and defend against insider threats?
(These questions are intended to be a self-test of your comprehension of this session’s material; answers to these questions do not need to be turned in.)
Summary
In Session 4 we took a first look at Snort, including the way the program components work and some of the implementation details and choices that go into planning a deployment of the tool. We also revisited the considerations behind IDS placement, with an emphasis on network-based IDS since that is Snort’s purpose.
Preview of Next Session
In the next session, we will continue focusing on Snort with an examination of the inner workings of a couple of the tool’s core components.
Copyright © 2016 UMUC – All rights reserved.
Welcome to one of the most trusted essay writing services with track record among students. We specialize in connecting students in need of high-quality essay writing help with skilled writers who can deliver just that. Explore the ratings of our essay writers and choose the one that best aligns with your requirements. When you rely on our online essay writing service, rest assured that you will receive a top-notch, plagiarism-free A-level paper. Our experienced professionals write each paper from scratch, carefully following your instructions. Request a paper from us and experience 100% originality.


