Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old September 10th, 2005, 12:27 PM
meditation meditation is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: Italy
Posts: 251 meditation User rank is Private First Class (20 - 50 Reputation Level)meditation User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 13 h 12 m 20 sec
Reputation Power: 6
Can I use Snort on a client instead of a server?

Hello everybody.I read(if I am wrong,I am sorry)that Snort is only for servers.Is there any way I can use it on a client instead?if this chance is already there,plz be so kind to tell me.Thanks in advance

Reply With Quote
  #2  
Old September 17th, 2005, 12:34 AM
jaaput jaaput is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Location: Zeist, Netherlands
Posts: 19 jaaput User rank is Lance Corporal (50 - 100 Reputation Level)jaaput User rank is Lance Corporal (50 - 100 Reputation Level)jaaput User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 16 h 15 m 4 sec
Reputation Power: 0
Basically snort is an application that tries to make a "profile",
or "behavior pattern", of network traffic, in order to signal
a sudden, strong change in that behavior.

Point here is that it has to be able to see the traffic.
Servers are (because of their often central role in a network)
a good candidate: they can see a great part of all the traffic
on the network, simply because they are part of most
conversations. Other good candidates are gateways,
they will be able to see all traffic that is traveling from a
network-segment towards another segment (mostly that
other segment being the Internet).
A normal workstation will only be able to see the traffic
on the segment which it is part of. And if the network
connections are made with a switch (as opposed to a hub)
it will only see the traffic that is broadcasted on the segment
(that is: explicitly sent to all connected hosts) and traffic
in which itself is one of the communicating hosts. But it
won't see any packet of what a neighbor workstation is
communicating with a server (or a gateway) in that very
same segment.

That's why i emphasized the phrase: able to see the traffic.
I think an ideal situation is that you use switches for all
your network segments (because switches do have great
advantages over hubs), but see to it that those switches
all have a monitoring port to which they deliver a copy of
each packet that travels through them.
Then you connect one or more PCs to those monitoring ports
and run snort on them. They will be able to see all the traffic,
and analyze it for you.

A little less ideal (but easier to configure and less expensive)
is that you install snort on all servers and possibly routers and
gateways in your network, and have them sent their data
to one of them (or a separate worksation) for analyzing purposes.

Now for a small network, with
  • just one or two segments,
  • a server that also performs the task of centralizing all
    Internet access (either by proxying and/or routing),
  • and non-managed switches (often only managed switches
    are equipped with a monitoring port, but they are much more
    expensive),
it is a very convenient solution to run snort on that server.
That will explain why you read that snort is for servers i guess.
But the location in the network is what counts, the ability to see network traffic.
And whether you analyze that on a server or a workstation is of less importance.

Regards, Jaap.
Comments on this post
kuza55 agrees!

Reply With Quote
  #3  
Old September 20th, 2005, 02:07 PM
meditation meditation is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: Italy
Posts: 251 meditation User rank is Private First Class (20 - 50 Reputation Level)meditation User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 13 h 12 m 20 sec
Reputation Power: 6
Thanks for your answer.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Can I use Snort on a client instead of a server?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway
Stay green...Green IT