Attacks/Breaches
5/28/2009
05:33 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Snort To Go Virtual

Open source IDS/IPS celebrates its tenth year with an all-new platform in the works, a new release candidate, and plans for a commercial a virtual appliance

The 10-year-old Snort IDS/IPS technology on which many of today's intrusion prevention products are based is poised for a face-lift.

Sourcefire, which develops the open source Snort tool, today officially announced that later this year it will deliver a commercial, Snort-based virtual appliance, and that it is working with Intel on the next-generation open source Snort engine. The company today also began offering a new release candidate of Snort, 2.8.5, and new features for version 2.8.4.

Snort has been gradually moving away from being just an IDS/IPS. Snort creator and Sourcefire CTO Martin Roesch last year first hinted at what Snort 3.0 might look like, revealing the next generation of the software would serve as a sort of a network traffic analysis platform on which other security functions could run.

And in a recent interview with Dark Reading, Roesch said Snort 3.0 -- currently under development -- will include the Snort Security Platform (SnortSP), providing the underlying processing for various security "applications" or functions that would handle traffic analysis, such as data leakage prevention and content scanning, in addition to IDS/IPS. "We would build network security applications on top of [the platform]," Roesch said.

Another Snort 3.0 element also under development is a new detection engine. "The Snort 3.0 detection engine is the second part of the project, which is a complete rewrite of Snort to run on the SP architecture," Roesch said. The Snort detection engine will replace Snort 2.X's detection engine, but SnortSP will be backward-compatible with earlier detection engines, he says.

"We're building a 3.0 engine architecture for the next 10 years," he said.

SnortSP is basically on operating system-like platform for network data: "It really allows the user base to plug in a lot more tools into that platform," Roesch says. "I don't want to sell futures, but just image a world where DLP, Netflow, NAC, NBA, IDS, IPS, etc., all run and are configurable on a common platform. [And] all can share data, and all can talk to each other."

As for Sourcefire's upcoming virtual Snort appliance, Roesch says it will be based on VMware ESX/ESXi, and that the company will formally announce its virtualization strategy by the end of the quarter. Aside from the obvious advantages of virtualizing IPSes at branch offices and for service providers to easily deploy IPS functions for their customers, a virtual Snort-based appliance also would provide VM-to-VM traffic inspection, he says.

Meanwhile, Snort 2.8.4 and Snort 2.8.5 are available for download here. Snort 2.8.4 features include improved support for preventing IPv6-borne attacks and enhanced NetBIOS traffic inspection. Snort 2.8.5 includes the ability to apply specific security policies for different VLAN functions, the ability to block rate-based attacks, and better handling of SSH traffic.

According to Sourcefire, Snort has more than 244,000 registered users; 80 percent of the Fortune 100 use Snort technology, while 42 percent of the Global 500 companies do.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-9676
Published: 2015-02-27
The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a crafted video that triggers a use after free.

CVE-2014-9682
Published: 2015-02-27
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.

CVE-2015-0655
Published: 2015-02-27
Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.

CVE-2015-0884
Published: 2015-02-27
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

CVE-2015-0885
Published: 2015-02-27
checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.