Snort mailing list archives
Event correlation engine?
From: Rich Adamson <radamson () routers com>
Date: Sun, 24 Aug 2003 09:22:47 -0600
Slightly off topic, but somewhat related.... Is anyone using some sort of event correlation engine that would analyze events from multiple sources (including snort, firewalls, etc), and generate a notification event in something close to real time? Looking for something that could handle this type of an example: a) firewall reports multiple blockages (assume port scan), b) snort on inside of firewall reports web unicode attack, and, c) IIS web server reports https page access from same source IP If these sequential events occur within some predetermined amount of time, generate a pager warning message (or something like that). I'm not looking for a perl script that runs every five minutes; rather, something that accepts alerts from commonly implemented devices and analyzes the sequence of events to generate near real-time alerts. Thoughts anyone? (Off list is fine if you want.) Rich ------------------------------------------------------- This SF.net email is sponsored by: VM Ware With VMware you can run multiple operating systems on a single machine. WITHOUT REBOOTING! Mix Linux / Windows / Novell virtual machines at the same time. Free trial click here:http://www.vmware.com/wl/offer/358/0 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Event correlation engine? Rich Adamson (Aug 24)
- Re: Event correlation engine? Jason Haar (Aug 25)
- Re: Event correlation engine? Rich Adamson (Aug 26)
- <Possible follow-ups>
- RE: Event correlation engine? Huober, Joachim (Aug 25)
- Re: Event correlation engine? JP Vossen (Aug 26)
- Re: Event correlation engine? Jason Haar (Aug 25)