OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: [snort] Dynamic Rules?
From: Vanja Hrustic (vanjarelaygroup.com)
Date: Wed Mar 22 2000 - 18:05:52 CST


David Klotz wrote:
> result of a break-in. What would really have been helpful at that point
> would have been the ability to start logging _all_ telnet traffic between
> our internal host and the suspect external one, and maybe even add a few
> more alerts that were specific to the suspect host. I've looked through the

David,

I wanted to make (which means: "I never did" :) a simple perl script
that would monitor the logs and when alert 'worth recording' occurs,
script would just invoke tcpdump (or snort), record the traffic for XY
minutes/seconds, and then terminate the tcpdump.

Now... the reson why I never actually did it is because I realized that
along with snort rules, I would need another set of rules for that
script (so that script knows what to do for which alert).

It would be a nightmare for maintenance (at that point, you basically
have 2 IDSs to maintain, not only 1 ;), but it might work as a temporary
solution. Until Marty integrates it into Snort ;))

-- 

Vanja Hrustic The Relay Group http://relaygroup.com Technology Ahead of Time