Snort mailing list archives

Re: Snort inline timeout


From: Joel Esler <jesler () sourcefire com>
Date: Thu, 30 Jul 2009 16:07:19 -0400

Well, I don't want to argue
semantics, Frank you know that.  SnortSAM activates after the alert
has taken place.  Brute force, yes, it will help in mitigating any
further hits on the target.

J

On Thu, Jul 30, 2009 at 4:05 PM, Frank Knobbe <frank () knobbe us> wrote:

On Thu, 2009-07-30 at 12:28 -0400, Joel Esler wrote:
Snortsam is an "after attack" enforcement system. Snort inline deals
with the attack during.

I take offense with that statement :)

Snortsam is an "after packet" enforcement system, while Snort Inline
deals with the packets.

Snortsam is well suited to stop brute force attacks. But the initial
packet or packets (however many required for the signature to fire) will
go through.

Cheers,
Frank


-- Joel Esler | Sourcefire | Google Voice: 302-223-5974
------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: