Attacks/Breaches
5/28/2009
05:33 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Snort To Go Virtual

Open source IDS/IPS celebrates its tenth year with an all-new platform in the works, a new release candidate, and plans for a commercial a virtual appliance

The 10-year-old Snort IDS/IPS technology on which many of today's intrusion prevention products are based is poised for a face-lift.

Sourcefire, which develops the open source Snort tool, today officially announced that later this year it will deliver a commercial, Snort-based virtual appliance, and that it is working with Intel on the next-generation open source Snort engine. The company today also began offering a new release candidate of Snort, 2.8.5, and new features for version 2.8.4.

Snort has been gradually moving away from being just an IDS/IPS. Snort creator and Sourcefire CTO Martin Roesch last year first hinted at what Snort 3.0 might look like, revealing the next generation of the software would serve as a sort of a network traffic analysis platform on which other security functions could run.

And in a recent interview with Dark Reading, Roesch said Snort 3.0 -- currently under development -- will include the Snort Security Platform (SnortSP), providing the underlying processing for various security "applications" or functions that would handle traffic analysis, such as data leakage prevention and content scanning, in addition to IDS/IPS. "We would build network security applications on top of [the platform]," Roesch said.

Another Snort 3.0 element also under development is a new detection engine. "The Snort 3.0 detection engine is the second part of the project, which is a complete rewrite of Snort to run on the SP architecture," Roesch said. The Snort detection engine will replace Snort 2.X's detection engine, but SnortSP will be backward-compatible with earlier detection engines, he says.

"We're building a 3.0 engine architecture for the next 10 years," he said.

SnortSP is basically on operating system-like platform for network data: "It really allows the user base to plug in a lot more tools into that platform," Roesch says. "I don't want to sell futures, but just image a world where DLP, Netflow, NAC, NBA, IDS, IPS, etc., all run and are configurable on a common platform. [And] all can share data, and all can talk to each other."

As for Sourcefire's upcoming virtual Snort appliance, Roesch says it will be based on VMware ESX/ESXi, and that the company will formally announce its virtualization strategy by the end of the quarter. Aside from the obvious advantages of virtualizing IPSes at branch offices and for service providers to easily deploy IPS functions for their customers, a virtual Snort-based appliance also would provide VM-to-VM traffic inspection, he says.

Meanwhile, Snort 2.8.4 and Snort 2.8.5 are available for download here. Snort 2.8.4 features include improved support for preventing IPv6-borne attacks and enhanced NetBIOS traffic inspection. Snort 2.8.5 includes the ability to apply specific security policies for different VLAN functions, the ability to block rate-based attacks, and better handling of SSH traffic.

According to Sourcefire, Snort has more than 244,000 registered users; 80 percent of the Fortune 100 use Snort technology, while 42 percent of the Global 500 companies do.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2003-1598
Published: 2014-10-01
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.

CVE-2011-4624
Published: 2014-10-01
Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.

CVE-2012-0811
Published: 2014-10-01
Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files gene...

CVE-2014-2640
Published: 2014-10-01
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-2641
Published: 2014-10-01
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.4 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Chris Hadnagy, who hosts the annual Social Engineering Capture the Flag Contest at DEF CON, will discuss the latest trends attackers are using.