Attacks/Breaches
5/28/2009
05:33 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Snort To Go Virtual

Open source IDS/IPS celebrates its tenth year with an all-new platform in the works, a new release candidate, and plans for a commercial a virtual appliance

The 10-year-old Snort IDS/IPS technology on which many of today's intrusion prevention products are based is poised for a face-lift.

Sourcefire, which develops the open source Snort tool, today officially announced that later this year it will deliver a commercial, Snort-based virtual appliance, and that it is working with Intel on the next-generation open source Snort engine. The company today also began offering a new release candidate of Snort, 2.8.5, and new features for version 2.8.4.

Snort has been gradually moving away from being just an IDS/IPS. Snort creator and Sourcefire CTO Martin Roesch last year first hinted at what Snort 3.0 might look like, revealing the next generation of the software would serve as a sort of a network traffic analysis platform on which other security functions could run.

And in a recent interview with Dark Reading, Roesch said Snort 3.0 -- currently under development -- will include the Snort Security Platform (SnortSP), providing the underlying processing for various security "applications" or functions that would handle traffic analysis, such as data leakage prevention and content scanning, in addition to IDS/IPS. "We would build network security applications on top of [the platform]," Roesch said.

Another Snort 3.0 element also under development is a new detection engine. "The Snort 3.0 detection engine is the second part of the project, which is a complete rewrite of Snort to run on the SP architecture," Roesch said. The Snort detection engine will replace Snort 2.X's detection engine, but SnortSP will be backward-compatible with earlier detection engines, he says.

"We're building a 3.0 engine architecture for the next 10 years," he said.

SnortSP is basically on operating system-like platform for network data: "It really allows the user base to plug in a lot more tools into that platform," Roesch says. "I don't want to sell futures, but just image a world where DLP, Netflow, NAC, NBA, IDS, IPS, etc., all run and are configurable on a common platform. [And] all can share data, and all can talk to each other."

As for Sourcefire's upcoming virtual Snort appliance, Roesch says it will be based on VMware ESX/ESXi, and that the company will formally announce its virtualization strategy by the end of the quarter. Aside from the obvious advantages of virtualizing IPSes at branch offices and for service providers to easily deploy IPS functions for their customers, a virtual Snort-based appliance also would provide VM-to-VM traffic inspection, he says.

Meanwhile, Snort 2.8.4 and Snort 2.8.5 are available for download here. Snort 2.8.4 features include improved support for preventing IPv6-borne attacks and enhanced NetBIOS traffic inspection. Snort 2.8.5 includes the ability to apply specific security policies for different VLAN functions, the ability to block rate-based attacks, and better handling of SSH traffic.

According to Sourcefire, Snort has more than 244,000 registered users; 80 percent of the Fortune 100 use Snort technology, while 42 percent of the Global 500 companies do.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2021
Published: 2014-10-24
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.4.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

CVE-2014-3604
Published: 2014-10-24
Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVE-2014-6230
Published: 2014-10-24
WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header.

CVE-2014-6251
Published: 2014-10-24
Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a mining.subscribe response with a large nonce2 length, then triggering the overflow with a mining.notify request.

CVE-2014-7180
Published: 2014-10-24
Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.