Attacks/Breaches
5/28/2009
05:33 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Snort To Go Virtual

Open source IDS/IPS celebrates its tenth year with an all-new platform in the works, a new release candidate, and plans for a commercial a virtual appliance

The 10-year-old Snort IDS/IPS technology on which many of today's intrusion prevention products are based is poised for a face-lift.

Sourcefire, which develops the open source Snort tool, today officially announced that later this year it will deliver a commercial, Snort-based virtual appliance, and that it is working with Intel on the next-generation open source Snort engine. The company today also began offering a new release candidate of Snort, 2.8.5, and new features for version 2.8.4.

Snort has been gradually moving away from being just an IDS/IPS. Snort creator and Sourcefire CTO Martin Roesch last year first hinted at what Snort 3.0 might look like, revealing the next generation of the software would serve as a sort of a network traffic analysis platform on which other security functions could run.

And in a recent interview with Dark Reading, Roesch said Snort 3.0 -- currently under development -- will include the Snort Security Platform (SnortSP), providing the underlying processing for various security "applications" or functions that would handle traffic analysis, such as data leakage prevention and content scanning, in addition to IDS/IPS. "We would build network security applications on top of [the platform]," Roesch said.

Another Snort 3.0 element also under development is a new detection engine. "The Snort 3.0 detection engine is the second part of the project, which is a complete rewrite of Snort to run on the SP architecture," Roesch said. The Snort detection engine will replace Snort 2.X's detection engine, but SnortSP will be backward-compatible with earlier detection engines, he says.

"We're building a 3.0 engine architecture for the next 10 years," he said.

SnortSP is basically on operating system-like platform for network data: "It really allows the user base to plug in a lot more tools into that platform," Roesch says. "I don't want to sell futures, but just image a world where DLP, Netflow, NAC, NBA, IDS, IPS, etc., all run and are configurable on a common platform. [And] all can share data, and all can talk to each other."

As for Sourcefire's upcoming virtual Snort appliance, Roesch says it will be based on VMware ESX/ESXi, and that the company will formally announce its virtualization strategy by the end of the quarter. Aside from the obvious advantages of virtualizing IPSes at branch offices and for service providers to easily deploy IPS functions for their customers, a virtual Snort-based appliance also would provide VM-to-VM traffic inspection, he says.

Meanwhile, Snort 2.8.4 and Snort 2.8.5 are available for download here. Snort 2.8.4 features include improved support for preventing IPv6-borne attacks and enhanced NetBIOS traffic inspection. Snort 2.8.5 includes the ability to apply specific security policies for different VLAN functions, the ability to block rate-based attacks, and better handling of SSH traffic.

According to Sourcefire, Snort has more than 244,000 registered users; 80 percent of the Fortune 100 use Snort technology, while 42 percent of the Global 500 companies do.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5427
Published: 2015-03-29
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read pa...

CVE-2014-5428
Published: 2015-03-29
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integratio...

CVE-2014-9205
Published: 2015-03-29
Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3.2 allows remote attackers to execute arbitrary code by providing a large amount of data.

CVE-2015-0528
Published: 2015-03-29
The RPC daemon in EMC Isilon OneFS 6.5.x and 7.0.x before 7.0.2.13, 7.1.0 before 7.1.0.6, 7.1.1 before 7.1.1.2, and 7.2.0 before 7.2.0.1 allows local users to gain privileges by leveraging an ability to modify system files.

CVE-2015-0996
Published: 2015-03-29
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive info...

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.