Snort 2.8.2.1 released
Snort is a lightweight network intrusion detection system, capable of performing real-time traffic analysis and packet logging on IP networks. It can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes such as buffer overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more. Snort uses a flexible rules language to describe traffic that it should collect or pass, as well as a detection engine that utilizes a modular plugin architecture. Snort has a real-time alerting capability as well, incorporating alerting mechanisms for syslog, a user specified file, a UNIX socket, or WinPopup messages to Windows clients using Samba’s smbclient.
Feature highlights:
- Port lists
- IPv6 support
- Packet performance monitoring
- Experimental support for target-based stream and IP frag reassembly
- Ability to take actions on preprocessor events
- Detection for TCP session hijacking based on MAC address
- Unified2 output plugin
- Improved performance and detection capabilities
ps :Thanks to Jim Taggert for reporting us this new release.
Post scriptum
Compliance Mandates
|
Related Articles
Data Sniffer |
|
IDS |
|
Snort |
|