FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.


» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Debian > Debian Development

 
 
LinkBack Thread Tools
 
Old 04-13-2008, 08:30 AM
Franck Joncourt
 
Default Bug#475822: ITP: fwsnort -- Fwsnort translates Snort rules into iptables rules.

Package: wnpp
Severity: wishlist
Owner: Franck Joncourt <franck.joncourt@wanadoo.fr>


* Package name : fwsnort
Version : 1.0.4
Upstream Author : Michael Rash <mbr@cipherdyne.org>
* URL : http://www.cipherdyne.org/fwsnort/
* License : GPL
Programming Lang: Perl
Description : Fwsnort translates Snort rules into iptables rules.

fwsnort translates Snort rules into iptables rules and generates a
Bourne shell script that implements the resulting iptables commands.
This ruleset allows network traffic that exhibits Snort signatures to
be logged and/or dropped by iptables directly without putting an
interface into promiscuous mode or queuing packets from kernel to user space.
Note that fwsnort can also build an iptables policy that combines the string
match extension with the NFQUEUE or QUEUE targets to allow the kernel to
perform preliminary string matches that are defined within Snort rules
before queuing matching packets to userspace. Because the bulk of
network communications are not malicious, this should provide a speedup
for snort_inline since the majority of packets do not then have to be
copied from kernel memory into user memory and subsequently inspected by
snort_inline. There is a tradeoff here in terms of signature detection
however because snort_inline does not have the opportunity to see all
packets associated with a session, so stream reassembly and signature
comparisons against a reassembled buffer do not take place (the stream
preprocessor - stream4, stream5, etc. - should be disabled).




--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
 

Thread Tools




All times are GMT. The time now is 05:26 AM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright 2007 - 2008, www.linux-archive.org