亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? faq.tex

?? This is the snapshot of Snot Latest Rules
?? TEX
?? 第 1 頁 / 共 5 頁
字號:
% $Id: faq.tex,v 1.11 2007/04/30 18:32:03 ssturges Exp $%latex2html -info 0 -local_icons -show_section_numbers -link 2 -split +1 faq.tex\documentclass{article}\usepackage{html}\usepackage{graphicx}\usepackage{fancyheadings}\usepackage{makeidx}%% Margins\oddsidemargin 0in\evensidemargin 0in\textwidth 6.5in\topmargin 0in\textheight 8in\setlength{\parindent}{0in}\setlength{\parskip}{.5\baselineskip}\pagestyle{fancy}\lhead{ {\sc Snort FAQ} }\cfoot{ {\sc feed the pig}}\rhead{Page \thepage}\newcommand{\myref}[1]{(see FAQ \ref{#1})}\newcommand{\myquote}[1]{\begin{quote}#1\end{quote}}%\label{key} assign current counter value to key%\myref{key}{print value assigned to key}% To emphasise% {\em blah}% To bold% {\bf bold face }% The following characters are special characters and need to be backslashed% before use:%    $ & % # _ { }%% To get a backslash, try $\backslash$\makeindex\begin{document}\title{ The Snort FAQ }\author{ The Snort Core Team }\date{ }% Title Page\maketitle\newpageSuggestions for enhancements of this document are always welcome.  Please email them to the \htmladdnormallink{Snort-Users}{mailto:snort-users@lists.sourceforge.net} mailing list. Many people have contributed to this FAQ:\begin{center}\begin{tabular}{llll} Marty Roesch   &  Fyodor Yarochkin    &   Dragos Ruiu      &     Jed Pickel\\    Max Vision   &    Michael Davis     &   Joe McAlerney    &      Joe Stewart\\    Erek Adams    &   Roman Danyliw   &   Christopher Cramer  &    Frank Knobbe\\     Phil Wood     & Toby Kohlenberg   &   Ramin Alidousti     &    Jim Hankins\\Dennis Hollingworth &  Paul Howell      &      Stef Mit         &   Ofir Arkin\\    Jason Haar       & Blake Frantz &  Lars Norman S?ndergaard  & Brent Erickson\\   Brian Caswell  &  Scot Wiedenfeld &       Chris Green        &   Jeff Wirth\\  Edin Dizdarevic  &  Detmar Liesen   &         Don Ng       &     Matt Kettler\\     Joe Lyman      &  Jim Burwell     &      Jed Haile      &   Andrew Hutchinson\\    Jeff Nathan   &  Alberto Gonzalez   &     Jason Haar    &    Jeremy Hewlett\end{tabular}\end{center}If you do not see your name on this list and you have contributed to the faq,please email \htmladdnormallink{bmc@snort.org}{mailto:bmc@snort.org}.Dragos Ruiu: This version of this guide has been brought to you by the kindgenerosity and sponsorship of Wiley and Sons publishers whose support letmyself, and other snort developers Jeff Nathan and Jed Haile take the time towork on this document and other tutorials for Snort due out in our upcomingbook. (route++)\newpage\begin{latexonly}\tableofcontents\newpage\end{latexonly}\section{Background}\subsection{How do you pronounce the names of some of these guys who work on Snort?}For the record, `Roesch' is pronounced like `fresh' without the `f.'  Additionally, `Ruiu' is pronounced like `screw you' without the `sc.'  Jed's last name is like `pick-el,' not `pickle.' \subsection{Is Fyodor Yarochkin the same Fyodor who wrote nmap?}Nope. fyodor@insecure.org is the author of nmap, and he uses the same pseudonym as the other Snort Fyodor's real surname. Yeah, it messes up my mailbox too, but I think it's too late to change either of them.\subsection{Where do I get more help on Snort?}Check the website, \htmladdnormallink{http://www.snort.org/}{http://www.snort.org/}.  Other good resources are available in the source distribution, including the \htmladdnormallink{Snort Users Manual}{http://www.snort.org/doc/SnortUsersManual.pdf} and the USAGE file. There is also a excellent mailing list, snort-users. You can findinfo on how to signup at \htmladdnormallink{http://www.snort.org/lists.html}{http://www.snort.org/lists.html}. You can also join \#snort on irc.freenode.net.\subsection{Where can I get more reading and courses about IDS?\label{courses}}All of the following offer courses on Intrusion Detection:\begin{itemize}\item \htmladdnormallink{SANS (http://www.sans.org)}{http://www.sans.org} \item \htmladdnormallink{Usenix (http://www.usenix.org/event/)}{http://www.usenix.org/event/} \item \htmladdnormallink{Networld/Interop (http://www.key3media.com/interop/)}{http://www.key3media.com/interop/}\item \htmladdnormallink{CanSecWest (http://www.cansecwest.com)}{http://www.cansecwest.com} \end{itemize}There are many good books on Intrusion Detection. Here are just a few:\begin{tabular}{|p{2in}|p{1.5in}|l|l|}\hline{\bf Title} & {\bf Author(s)} & {\bf Publisher} & {\bf ISBN}\\\hline\hlineSnort 2.1 Intrusion Detection, Second Edition & Brian Caswell, Jay Beale & 1931836043 \\\hlineTao of Network Security Monitoring, The: Beyond Intrusion Detection & Richard Bejtlich & 0321246772 \\\hlineIntrusion Detection with Snort: Advanced IDS Techniques & Rafeeq Rehman & Prentice Hall & I0131407333\\\hlineSnort Intrusion Detection        &       Ryan Russell        & Syngress Media &  1931836744 \\\hlineSnort Intrusion Detection        &        Jack Koziol        &   New Riders   &  157870281X\\\hlineNetwork Intrusion Detection: An Analyst's Handbook & Stephen Northcutt & New Riders & 0735708681 \\\hlineIntrusion Signatures and Analysis                 & Stephen Northcutt & New Riders & 0735710635 \\\hlineTCP/IP Illustrated, Volume 1 The Protocols        & W. Richard Stevens & Addison-Wesley & 0201633469 \\\hlineIntrusion Detection                               & Rebecca G. Bace    & MacMillan Technical Publishing & 1578701856 \\\hlineThe Tao of Network Security Monitoring: Beyond Intrusion Detection & Richard Bejtlich & Addison-Wesley & 0321246772 \\\hlineSnort 2.1 Intrusion Detection, Second Edition & Brian Caswell \& Jay Beale & Syngress Publishing & 1931836043 \\\hline\end{tabular}	\subsection{Does Snort handle IP defragmentation?}Yes, use {\tt preprocessor frag3}.\subsection{Does Snort perform TCP stream reassembly?}Yes, check out the stream4 preprocessor \myref{stream4} that does stateful analysis session login, TCP reassembly and much, much more.\subsection{Does Snort perform stateful protocol analysis?}Yes. Stream4 does this as well. See \myref{stream4}.\subsection{I'm on a switched network, can I still use Snort?}{\bf Short version:}Being able to sniff on a switched network depends on what type of switch isbeing used. If the switch can mirror traffic, then set the switch to mirror alltraffic to the Snort machine's port.{\bf Extended version:}There are several ways of deploying NIDS in switched environments which allhave their pros and cons. Which method applies to your needs depends on whatkind of segments you want to monitor and on your budget. Here are the mostcommon methods:\begin{enumerate}\item  {\bf Switch mirror:} If the switch can mirror traffic, then set the switch to    mirror all traffic to the Snort machine's port.   \begin{itemize}   	\item Advantages:	      \begin{itemize}              \item Simple method, works with most decent switches.	      \end{itemize}	 \item Drawbacks:	      \begin{itemize}              \item If the switch is a fast Ethernet switch, you can mirror 100Mbit/s	      max. Since each switch port is capable of handling 100Mbit/s for each	      direction, the bandwidth per port sums up to 200Mbit/s, so the switch	      will not be able to mirror all packets at high network utilization.	      \item Some switches suffer from performance degradation through port	      mirroring.	      \end{itemize}    \end{itemize}\item  {\bf Hub:} Insert a hub in line, so you can simply tap all traffic. Works    fine for home networks, will lose data due to collisions at loads greater    than 50\%---so a 10Mbps hub should be fine for T1/E1, DSL or cablemodem. If    you have a DS3 or greater, you should investigate taps.    \begin{itemize}      \item Advantages:      		\begin{itemize}		\item Simple method		\item No impact on switch performance and no config changes		\item Low cost		\end{itemize}      \item Drawbacks:      		\begin{itemize}		\item Loss of full-duplex capabilities		\item Additional single point of failure		\item Collision loss at above 50\% load levels		\end{itemize}    \end{itemize}\item  {\bf Network taps:} Use network taps (e.g. Shomiti/Finisar [\htmladdnormallink{http://www.shomiti.com}{http://www.shomiti.com}] and Netoptics [\htmladdnormallink{http://www.netoptics.com}{http://www.netoptics.com}). You can find some rather good information in the papers by Jeff  Nathan. You can find the papers at     \htmladdnormallink{http://www.snort.org/docs/\#deploy}{http://www.snort.org/docs/\#deploy}.      \begin{itemize}      \item Advantages:      		\begin{itemize}		\item No impact on switch performance and no special configuration		\item Stealth---i.e., sending data back to the switch is disabled		\item No single point of failure, ``fail-open'' if the tap power fails		\end{itemize}      \item Drawbacks:		\begin{itemize}		\item The datastream is split into TX and RX, so you need two NICs		\item The two datastreams have to be recombined, i.e. merged, if you don't		want to lose the capability of doing stateful analysis. This can be		done by using channel bonding. Information can be found at 		\htmladdnormallink{http://sourceforge.net/projects/bonding}{http://sourceforge.net/projects/bonding}.		\item Cost		\end{itemize}      \end{itemize}	\item  {\bf Throw money at it:} Tap switch ports (using the forementioned    network taps) but only tap all incoming packets (RX lines of the switch    ports), connecting those tap ports to a dedicated gigabit switch, which is    capable of mirroring up to ten RX taplines to one single dedicated gigabit    port, which is connected to a gigabit IDS machine.    \begin{itemize}      \item Advantages:      		\begin{itemize}        	\item Maximum coverage (i.e. monitor all switchports)		\item No performance degradation or re-configuration of the switch		\end{itemize}      \item Drawbacks:      		\begin{itemize}		\item Mucho \$\$\$		\end{itemize}    \end{itemize}\end{enumerate}\subsection{Is Snort vulnerable to IDS noise generators like ``Stick'' and ``Snot''?}It is now possible to defeat these kinds of noise generators withthe stream4 preprocessor (see \myref{stream4}).  Even without the stream4 preprocessor enabled, Snort will weather the alert storm without falling over or losing a lot of alerts due to its highly optimized nature.  Using tools that generate huge amounts of alerts will warn a good analyst that someone is trying to sneak by their defenses.  \subsection{Can Snort be evaded by the use of polymorphic mutators on shellcode?}Yes, and this could defeat some of the NOP sled detection signatures,but the ordinary exploit rules should not be affected by this kindof obfuscation.  The fnord preprocessor attempts to detect polymorphicshellcode attempts.\subsection{Does Snort log the full packets when it generates alerts? }Yes, the packets should be in the directory that has the same IP address as thesource host of the packet which generated the alert. If you are using binarylogging, there will be a packet capture file (.pcap) in the logging directoryinstead.  \section{Getting Started}\subsection{Where do I find binary packages for BlueHat BSD-Linux-RT?}Repeat after me:\begin{verbatim}    wget http://www.snort.org/downloads/snort-stable.tgz    tar zxvf snort-stable.tgz    cd snort-stable    ./configure    make    su    make install    mkdir /var/log/snort    cd etc    vi snort.conf    snort -D -c snort.conf    exit\end{verbatim}...and if you want to use our binary package uninstaller :-):\begin{verbatim}    cd snort-stable; make uninstall\end{verbatim}And if you must, you can find some binaries at \htmladdnormallink{http://www.snort.org/dl/binaries/}{http://www.snort.org/dl/binaries/}. You can also find Snort in most BSD ports' trees.\subsection{How do I run Snort?}Run Snort in sniffer mode and make sure it can see the packets.  \begin{verbatim}snort -dv\end{verbatim}

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
亚洲在线观看免费| 色综合久久天天综合网| 顶级嫩模精品视频在线看| 91免费视频网址| 精品久久久久久久久久久久久久久久久| 国产欧美在线观看一区| 亚洲1区2区3区视频| 成人午夜私人影院| 91精品国产91久久综合桃花| 亚洲日本电影在线| 国产成人精品午夜视频免费| 欧美日韩国产经典色站一区二区三区| 中文幕一区二区三区久久蜜桃| 免费一级片91| 欧美日韩二区三区| 一区二区成人在线视频| 成人白浆超碰人人人人| 精品国产露脸精彩对白 | 国产高清不卡一区二区| 欧美日韩激情一区二区三区| 有码一区二区三区| 99久久精品免费| 中文av字幕一区| 成人免费视频一区| 国产清纯白嫩初高生在线观看91| 国产一区二区三区在线观看免费| 日韩一区二区三免费高清| 视频一区二区三区入口| 在线不卡免费欧美| 日本亚洲欧美天堂免费| 91精品国产福利| 日本女优在线视频一区二区| 欧美一区二区三区在线| 琪琪一区二区三区| 亚洲精品一区在线观看| 国产一区二区三区| 中文字幕欧美日韩一区| 丁香激情综合五月| 亚洲蜜臀av乱码久久精品| 在线日韩av片| 日韩中文字幕亚洲一区二区va在线| 欧美视频一区二区三区四区 | 91麻豆精品国产91久久久| 亚洲成a人片综合在线| 欧美私人免费视频| 蜜芽一区二区三区| 精品国产髙清在线看国产毛片| 国产一区二区三区四区五区入口| 久久色中文字幕| 成人av免费在线| 亚洲自拍偷拍图区| 精品国产一二三| 成人v精品蜜桃久久一区| 一区二区高清在线| 26uuu成人网一区二区三区| 国产激情视频一区二区三区欧美| 久久久久久久一区| 色婷婷综合久久| 日韩经典一区二区| 欧美国产精品一区| 欧美日韩另类一区| 国产成人在线视频网址| 亚洲最新视频在线观看| 欧美tickle裸体挠脚心vk| 成人国产精品视频| 视频一区二区三区入口| 国产欧美日韩精品在线| 欧美熟乱第一页| 国产馆精品极品| 爽爽淫人综合网网站| 国产人妖乱国产精品人妖| 日本精品免费观看高清观看| 狠狠色综合日日| 亚洲综合免费观看高清完整版| 精品国产免费人成在线观看| 色视频一区二区| 国产精品一区二区三区四区| 亚洲超碰97人人做人人爱| 国产欧美一区二区精品仙草咪| 欧美伊人久久大香线蕉综合69| 国产麻豆精品在线观看| 一区二区三区四区乱视频| 久久精品亚洲一区二区三区浴池 | 久久精品一区蜜桃臀影院| 欧美日韩亚州综合| 成人禁用看黄a在线| 免费在线看成人av| 亚洲国产一区视频| 日韩久久一区二区| 久久精品亚洲精品国产欧美kt∨| 91成人免费在线| a级高清视频欧美日韩| 国产一区二区三区视频在线播放| 日韩精品成人一区二区在线| 亚洲永久免费av| 成人免费小视频| 国产精品网站在线观看| 久久一区二区三区四区| 欧美成人乱码一区二区三区| 欧美日韩国产一级片| 欧美日韩的一区二区| 欧美在线高清视频| 精品视频在线免费看| 欧美丝袜丝交足nylons| 欧美优质美女网站| 欧美亚洲一区三区| 欧美午夜在线一二页| 欧美日韩一区中文字幕| 欧美日韩亚洲高清一区二区| 欧美日韩精品欧美日韩精品| 欧美日韩国产bt| 777色狠狠一区二区三区| 欧美高清性hdvideosex| 欧美日韩一本到| 69堂成人精品免费视频| 欧美一区二区三区免费视频| 日韩免费性生活视频播放| 精品区一区二区| 国产农村妇女精品| 国产精品久久久久久福利一牛影视| 国产欧美日韩三级| 亚洲人成伊人成综合网小说| 一区二区三区在线影院| 亚洲福中文字幕伊人影院| 丝袜美腿亚洲综合| 蓝色福利精品导航| 国产suv精品一区二区三区| 97久久精品人人澡人人爽| 在线视频一区二区三区| 欧美一级免费大片| 久久影院视频免费| 综合久久给合久久狠狠狠97色| 曰韩精品一区二区| 久久国产麻豆精品| 成人app下载| 欧美在线三级电影| 日韩欧美不卡在线观看视频| 国产日本亚洲高清| 亚洲高清免费在线| 国产一区二区不卡| 色婷婷av一区二区三区gif| 欧美一区二区免费观在线| 久久伊人中文字幕| 亚洲综合色噜噜狠狠| 国产专区欧美精品| 日本韩国欧美在线| 精品国产一区二区三区四区四| 最新久久zyz资源站| 亚洲图片欧美综合| 岛国精品一区二区| 欧美日韩视频在线第一区 | 欧洲精品一区二区三区在线观看| 欧美人动与zoxxxx乱| 久久精品一区二区三区不卡牛牛| 亚洲欧美日韩在线| 黄页视频在线91| 欧美丝袜丝nylons| 中国色在线观看另类| 日韩福利电影在线| 色综合久久中文字幕综合网| 精品国产百合女同互慰| 亚洲v日本v欧美v久久精品| 国产成人免费在线观看不卡| 欧美夫妻性生活| 亚洲女女做受ⅹxx高潮| 精品一区二区三区免费播放| 欧美日韩综合在线免费观看| 国产精品美女视频| 精品影视av免费| 91精品福利在线一区二区三区| 一区二区三区在线播| 国产69精品久久99不卡| 91精品一区二区三区久久久久久| 亚洲男同性视频| 成人av片在线观看| 日本一区二区三区国色天香| 免费观看91视频大全| 欧美久久久一区| 一区二区高清在线| 91蜜桃在线免费视频| 日本一区二区久久| 国产一区91精品张津瑜| 日韩欧美精品三级| 免费三级欧美电影| 日韩一级片在线播放| 亚洲1区2区3区4区| 欧美欧美午夜aⅴ在线观看| 亚洲人成在线播放网站岛国| 99麻豆久久久国产精品免费优播| 久久精品亚洲精品国产欧美kt∨ | 国产精品久久福利| 国产很黄免费观看久久| 久久精品亚洲一区二区三区浴池| 国内精品免费在线观看| 久久女同互慰一区二区三区| 精品系列免费在线观看| 久久精品一二三| 成人免费av在线| 亚洲图片激情小说| 在线看日本不卡|