fwsnort translates snort rules into an equivalent iptables ruleset. By making use of the iptables string match module, fwsnort can detect application layer signatures which exist in many snort rules. fwsnort adds a --hex-string option to iptables, which allows snort rules that contain hex characters to be input directly into iptables rulesets without modification. In addition, fwsnort makes use of the IPTables:arse Perl module in order to (optionally) restrict the snort rule translation to only those rules that specify traffic that could potentially be allowed through an existing iptables policy. __________ powered by http://different-thinking.de - Netze, Protokolle, Sicherheit, ...
Um auf dieses Thema zu ANTWORTEN bitte erst » hier kostenlos registrieren!!
by Michael Rash
Relevant URL:
http://www.cipherdyne.com/fwsnort/
Platforms: Linux
Summary:
fwsnort translates snort rules into an equivalent iptables ruleset. By
making use of the iptables string match module, fwsnort can detect
application layer signatures which exist in many snort rules. fwsnort adds
a --hex-string option to iptables, which allows snort rules that contain
hex characters to be input directly into iptables rulesets without
modification. In addition, fwsnort makes use of the IPTables:arse Perl
module in order to (optionally) restrict the snort rule translation to
only those rules that specify traffic that could potentially be allowed
through an existing iptables policy.
__________
powered by http://different-thinking.de - Netze, Protokolle, Sicherheit, ...