亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? faq.tex

?? This is the snapshot of Snot Latest Rules
?? TEX
?? 第 1 頁 / 共 5 頁
字號:
% $Id: faq.tex,v 1.11 2007/04/30 18:32:03 ssturges Exp $%latex2html -info 0 -local_icons -show_section_numbers -link 2 -split +1 faq.tex\documentclass{article}\usepackage{html}\usepackage{graphicx}\usepackage{fancyheadings}\usepackage{makeidx}%% Margins\oddsidemargin 0in\evensidemargin 0in\textwidth 6.5in\topmargin 0in\textheight 8in\setlength{\parindent}{0in}\setlength{\parskip}{.5\baselineskip}\pagestyle{fancy}\lhead{ {\sc Snort FAQ} }\cfoot{ {\sc feed the pig}}\rhead{Page \thepage}\newcommand{\myref}[1]{(see FAQ \ref{#1})}\newcommand{\myquote}[1]{\begin{quote}#1\end{quote}}%\label{key} assign current counter value to key%\myref{key}{print value assigned to key}% To emphasise% {\em blah}% To bold% {\bf bold face }% The following characters are special characters and need to be backslashed% before use:%    $ & % # _ { }%% To get a backslash, try $\backslash$\makeindex\begin{document}\title{ The Snort FAQ }\author{ The Snort Core Team }\date{ }% Title Page\maketitle\newpageSuggestions for enhancements of this document are always welcome.  Please email them to the \htmladdnormallink{Snort-Users}{mailto:snort-users@lists.sourceforge.net} mailing list. Many people have contributed to this FAQ:\begin{center}\begin{tabular}{llll} Marty Roesch   &  Fyodor Yarochkin    &   Dragos Ruiu      &     Jed Pickel\\    Max Vision   &    Michael Davis     &   Joe McAlerney    &      Joe Stewart\\    Erek Adams    &   Roman Danyliw   &   Christopher Cramer  &    Frank Knobbe\\     Phil Wood     & Toby Kohlenberg   &   Ramin Alidousti     &    Jim Hankins\\Dennis Hollingworth &  Paul Howell      &      Stef Mit         &   Ofir Arkin\\    Jason Haar       & Blake Frantz &  Lars Norman S?ndergaard  & Brent Erickson\\   Brian Caswell  &  Scot Wiedenfeld &       Chris Green        &   Jeff Wirth\\  Edin Dizdarevic  &  Detmar Liesen   &         Don Ng       &     Matt Kettler\\     Joe Lyman      &  Jim Burwell     &      Jed Haile      &   Andrew Hutchinson\\    Jeff Nathan   &  Alberto Gonzalez   &     Jason Haar    &    Jeremy Hewlett\end{tabular}\end{center}If you do not see your name on this list and you have contributed to the faq,please email \htmladdnormallink{bmc@snort.org}{mailto:bmc@snort.org}.Dragos Ruiu: This version of this guide has been brought to you by the kindgenerosity and sponsorship of Wiley and Sons publishers whose support letmyself, and other snort developers Jeff Nathan and Jed Haile take the time towork on this document and other tutorials for Snort due out in our upcomingbook. (route++)\newpage\begin{latexonly}\tableofcontents\newpage\end{latexonly}\section{Background}\subsection{How do you pronounce the names of some of these guys who work on Snort?}For the record, `Roesch' is pronounced like `fresh' without the `f.'  Additionally, `Ruiu' is pronounced like `screw you' without the `sc.'  Jed's last name is like `pick-el,' not `pickle.' \subsection{Is Fyodor Yarochkin the same Fyodor who wrote nmap?}Nope. fyodor@insecure.org is the author of nmap, and he uses the same pseudonym as the other Snort Fyodor's real surname. Yeah, it messes up my mailbox too, but I think it's too late to change either of them.\subsection{Where do I get more help on Snort?}Check the website, \htmladdnormallink{http://www.snort.org/}{http://www.snort.org/}.  Other good resources are available in the source distribution, including the \htmladdnormallink{Snort Users Manual}{http://www.snort.org/doc/SnortUsersManual.pdf} and the USAGE file. There is also a excellent mailing list, snort-users. You can findinfo on how to signup at \htmladdnormallink{http://www.snort.org/lists.html}{http://www.snort.org/lists.html}. You can also join \#snort on irc.freenode.net.\subsection{Where can I get more reading and courses about IDS?\label{courses}}All of the following offer courses on Intrusion Detection:\begin{itemize}\item \htmladdnormallink{SANS (http://www.sans.org)}{http://www.sans.org} \item \htmladdnormallink{Usenix (http://www.usenix.org/event/)}{http://www.usenix.org/event/} \item \htmladdnormallink{Networld/Interop (http://www.key3media.com/interop/)}{http://www.key3media.com/interop/}\item \htmladdnormallink{CanSecWest (http://www.cansecwest.com)}{http://www.cansecwest.com} \end{itemize}There are many good books on Intrusion Detection. Here are just a few:\begin{tabular}{|p{2in}|p{1.5in}|l|l|}\hline{\bf Title} & {\bf Author(s)} & {\bf Publisher} & {\bf ISBN}\\\hline\hlineSnort 2.1 Intrusion Detection, Second Edition & Brian Caswell, Jay Beale & 1931836043 \\\hlineTao of Network Security Monitoring, The: Beyond Intrusion Detection & Richard Bejtlich & 0321246772 \\\hlineIntrusion Detection with Snort: Advanced IDS Techniques & Rafeeq Rehman & Prentice Hall & I0131407333\\\hlineSnort Intrusion Detection        &       Ryan Russell        & Syngress Media &  1931836744 \\\hlineSnort Intrusion Detection        &        Jack Koziol        &   New Riders   &  157870281X\\\hlineNetwork Intrusion Detection: An Analyst's Handbook & Stephen Northcutt & New Riders & 0735708681 \\\hlineIntrusion Signatures and Analysis                 & Stephen Northcutt & New Riders & 0735710635 \\\hlineTCP/IP Illustrated, Volume 1 The Protocols        & W. Richard Stevens & Addison-Wesley & 0201633469 \\\hlineIntrusion Detection                               & Rebecca G. Bace    & MacMillan Technical Publishing & 1578701856 \\\hlineThe Tao of Network Security Monitoring: Beyond Intrusion Detection & Richard Bejtlich & Addison-Wesley & 0321246772 \\\hlineSnort 2.1 Intrusion Detection, Second Edition & Brian Caswell \& Jay Beale & Syngress Publishing & 1931836043 \\\hline\end{tabular}	\subsection{Does Snort handle IP defragmentation?}Yes, use {\tt preprocessor frag3}.\subsection{Does Snort perform TCP stream reassembly?}Yes, check out the stream4 preprocessor \myref{stream4} that does stateful analysis session login, TCP reassembly and much, much more.\subsection{Does Snort perform stateful protocol analysis?}Yes. Stream4 does this as well. See \myref{stream4}.\subsection{I'm on a switched network, can I still use Snort?}{\bf Short version:}Being able to sniff on a switched network depends on what type of switch isbeing used. If the switch can mirror traffic, then set the switch to mirror alltraffic to the Snort machine's port.{\bf Extended version:}There are several ways of deploying NIDS in switched environments which allhave their pros and cons. Which method applies to your needs depends on whatkind of segments you want to monitor and on your budget. Here are the mostcommon methods:\begin{enumerate}\item  {\bf Switch mirror:} If the switch can mirror traffic, then set the switch to    mirror all traffic to the Snort machine's port.   \begin{itemize}   	\item Advantages:	      \begin{itemize}              \item Simple method, works with most decent switches.	      \end{itemize}	 \item Drawbacks:	      \begin{itemize}              \item If the switch is a fast Ethernet switch, you can mirror 100Mbit/s	      max. Since each switch port is capable of handling 100Mbit/s for each	      direction, the bandwidth per port sums up to 200Mbit/s, so the switch	      will not be able to mirror all packets at high network utilization.	      \item Some switches suffer from performance degradation through port	      mirroring.	      \end{itemize}    \end{itemize}\item  {\bf Hub:} Insert a hub in line, so you can simply tap all traffic. Works    fine for home networks, will lose data due to collisions at loads greater    than 50\%---so a 10Mbps hub should be fine for T1/E1, DSL or cablemodem. If    you have a DS3 or greater, you should investigate taps.    \begin{itemize}      \item Advantages:      		\begin{itemize}		\item Simple method		\item No impact on switch performance and no config changes		\item Low cost		\end{itemize}      \item Drawbacks:      		\begin{itemize}		\item Loss of full-duplex capabilities		\item Additional single point of failure		\item Collision loss at above 50\% load levels		\end{itemize}    \end{itemize}\item  {\bf Network taps:} Use network taps (e.g. Shomiti/Finisar [\htmladdnormallink{http://www.shomiti.com}{http://www.shomiti.com}] and Netoptics [\htmladdnormallink{http://www.netoptics.com}{http://www.netoptics.com}). You can find some rather good information in the papers by Jeff  Nathan. You can find the papers at     \htmladdnormallink{http://www.snort.org/docs/\#deploy}{http://www.snort.org/docs/\#deploy}.      \begin{itemize}      \item Advantages:      		\begin{itemize}		\item No impact on switch performance and no special configuration		\item Stealth---i.e., sending data back to the switch is disabled		\item No single point of failure, ``fail-open'' if the tap power fails		\end{itemize}      \item Drawbacks:		\begin{itemize}		\item The datastream is split into TX and RX, so you need two NICs		\item The two datastreams have to be recombined, i.e. merged, if you don't		want to lose the capability of doing stateful analysis. This can be		done by using channel bonding. Information can be found at 		\htmladdnormallink{http://sourceforge.net/projects/bonding}{http://sourceforge.net/projects/bonding}.		\item Cost		\end{itemize}      \end{itemize}	\item  {\bf Throw money at it:} Tap switch ports (using the forementioned    network taps) but only tap all incoming packets (RX lines of the switch    ports), connecting those tap ports to a dedicated gigabit switch, which is    capable of mirroring up to ten RX taplines to one single dedicated gigabit    port, which is connected to a gigabit IDS machine.    \begin{itemize}      \item Advantages:      		\begin{itemize}        	\item Maximum coverage (i.e. monitor all switchports)		\item No performance degradation or re-configuration of the switch		\end{itemize}      \item Drawbacks:      		\begin{itemize}		\item Mucho \$\$\$		\end{itemize}    \end{itemize}\end{enumerate}\subsection{Is Snort vulnerable to IDS noise generators like ``Stick'' and ``Snot''?}It is now possible to defeat these kinds of noise generators withthe stream4 preprocessor (see \myref{stream4}).  Even without the stream4 preprocessor enabled, Snort will weather the alert storm without falling over or losing a lot of alerts due to its highly optimized nature.  Using tools that generate huge amounts of alerts will warn a good analyst that someone is trying to sneak by their defenses.  \subsection{Can Snort be evaded by the use of polymorphic mutators on shellcode?}Yes, and this could defeat some of the NOP sled detection signatures,but the ordinary exploit rules should not be affected by this kindof obfuscation.  The fnord preprocessor attempts to detect polymorphicshellcode attempts.\subsection{Does Snort log the full packets when it generates alerts? }Yes, the packets should be in the directory that has the same IP address as thesource host of the packet which generated the alert. If you are using binarylogging, there will be a packet capture file (.pcap) in the logging directoryinstead.  \section{Getting Started}\subsection{Where do I find binary packages for BlueHat BSD-Linux-RT?}Repeat after me:\begin{verbatim}    wget http://www.snort.org/downloads/snort-stable.tgz    tar zxvf snort-stable.tgz    cd snort-stable    ./configure    make    su    make install    mkdir /var/log/snort    cd etc    vi snort.conf    snort -D -c snort.conf    exit\end{verbatim}...and if you want to use our binary package uninstaller :-):\begin{verbatim}    cd snort-stable; make uninstall\end{verbatim}And if you must, you can find some binaries at \htmladdnormallink{http://www.snort.org/dl/binaries/}{http://www.snort.org/dl/binaries/}. You can also find Snort in most BSD ports' trees.\subsection{How do I run Snort?}Run Snort in sniffer mode and make sure it can see the packets.  \begin{verbatim}snort -dv\end{verbatim}

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
日韩一区欧美一区| 亚洲国产精品99久久久久久久久| 久久精品一区二区三区av| 亚洲欧洲制服丝袜| 精品亚洲国产成人av制服丝袜| 一本一本大道香蕉久在线精品 | 国产精品久久一级| 欧美aaa在线| 在线精品视频免费观看| 国产精品欧美一区二区三区| 精品综合久久久久久8888| 欧美亚洲日本一区| 亚洲乱码国产乱码精品精可以看| 国产精选一区二区三区| 日韩小视频在线观看专区| 亚洲超丰满肉感bbw| 91一区二区在线观看| 国产精品毛片高清在线完整版| 国产最新精品免费| 日韩欧美电影一二三| 亚洲国产一二三| 麻豆中文一区二区| 欧美视频中文一区二区三区在线观看| 国产精品你懂的| 韩国v欧美v日本v亚洲v| 宅男在线国产精品| 一区二区三区四区在线免费观看 | 欧美日韩一区二区三区在线看| 久久这里只有精品6| 日本在线不卡视频一二三区| av色综合久久天堂av综合| 欧美成人精品高清在线播放| 午夜精品久久久久久久 | 日韩一级黄色大片| 亚洲欧美一区二区不卡| 成人av在线一区二区| 久久久久久99精品| 国产经典欧美精品| 久久亚洲一级片| 精品一区二区三区av| 日韩精品中文字幕在线不卡尤物 | 精品99久久久久久| 日韩电影一二三区| 欧美日韩精品系列| 亚洲成在线观看| 色综合一区二区三区| 最好看的中文字幕久久| 成人黄色免费短视频| 中文字幕第一区| 成人性生交大合| 日本一区二区三区久久久久久久久不| 韩国女主播成人在线| 精品国产制服丝袜高跟| 国内精品在线播放| 日韩精品自拍偷拍| 大白屁股一区二区视频| 国产精品久久久久久久久快鸭 | 欧美综合色免费| 水蜜桃久久夜色精品一区的特点| 欧美色图在线观看| 爽爽淫人综合网网站| 日韩美女视频在线| 国产成人综合在线| 69久久夜色精品国产69蝌蚪网| 天堂久久一区二区三区| 日韩免费一区二区三区在线播放| 国产伦精一区二区三区| 亚洲欧美在线视频| 欧美日韩在线播| 狠狠狠色丁香婷婷综合久久五月| 国产日产亚洲精品系列| 91在线精品一区二区| 舔着乳尖日韩一区| 精品国产乱码久久久久久1区2区| 国产精品一区不卡| 亚洲一级二级三级在线免费观看| 欧美三级中文字幕在线观看| 久久99精品一区二区三区| 亚洲婷婷在线视频| 91豆麻精品91久久久久久| 蜜桃一区二区三区四区| www国产精品av| 国产高清精品网站| 亚洲福利视频三区| 久久精品欧美日韩| 欧美视频日韩视频在线观看| 国产在线精品一区二区不卡了| 欧美极品另类videosde| 欧美中文字幕一区二区三区 | 国产成人av网站| 玉米视频成人免费看| 日韩欧美综合在线| 色哦色哦哦色天天综合| 首页国产欧美久久| 自拍偷拍亚洲欧美日韩| 日韩精品中文字幕一区| 欧美专区日韩专区| 不卡的av在线| 久久69国产一区二区蜜臀| 亚洲另类春色国产| 国产亚洲人成网站| 欧美日韩国产一区二区三区地区| 精品无人区卡一卡二卡三乱码免费卡| 中文字幕制服丝袜一区二区三区 | 亚洲蜜臀av乱码久久精品蜜桃| 日韩欧美专区在线| 欧美系列日韩一区| 97久久精品人人澡人人爽| 久久99国内精品| 午夜a成v人精品| 亚洲人成网站精品片在线观看| 日韩美女视频在线| 91精品国产综合久久国产大片 | 天天色图综合网| 久久久国际精品| 日韩欧美国产一区二区三区| 在线成人av网站| 欧美在线你懂的| 色婷婷久久久亚洲一区二区三区 | 欧美日韩国产精选| 一本大道久久a久久精二百| 懂色av一区二区在线播放| 久久99久久99| 久久国产精品72免费观看| 日韩中文字幕1| 丝袜美腿成人在线| 人人精品人人爱| 日本强好片久久久久久aaa| 一区二区三区中文字幕| 91精品在线麻豆| 精品国产在天天线2019| 精品国产乱码久久久久久闺蜜| 欧美成人一区二区三区在线观看| 日韩欧美一级在线播放| 日韩免费观看高清完整版| 91精品国产综合久久久蜜臀图片| 制服丝袜亚洲色图| 日韩免费观看高清完整版| 精品国产1区2区3区| 国产欧美日本一区二区三区| 国产女主播在线一区二区| 国产精品久久久久久久久免费丝袜| 国产精品视频一二三区| 亚洲天堂成人在线观看| 一区二区三区四区亚洲| 亚洲成人777| 久久精品免费观看| 国产黄色精品视频| 色偷偷久久人人79超碰人人澡| 在线观看欧美日本| 日韩限制级电影在线观看| 精品黑人一区二区三区久久 | 色噜噜狠狠色综合欧洲selulu| 日本高清不卡在线观看| 欧美日韩国产精选| 久久久久久久久免费| 国产精品乱码久久久久久| 亚洲在线观看免费视频| 蜜桃精品视频在线观看| 国产一区二区三区在线观看免费视频 | 国产区在线观看成人精品| 国产精品成人在线观看| 香蕉av福利精品导航| 国产一区二区三区免费| 一本高清dvd不卡在线观看| 7878成人国产在线观看| 国产视频一区二区在线观看| 久久网站热最新地址| 中文字幕亚洲一区二区va在线| 日本欧美韩国一区三区| 成人av手机在线观看| 欧美老肥妇做.爰bbww| 久久久精品影视| 香港成人在线视频| 成人精品鲁一区一区二区| 欧美日韩国产小视频在线观看| 精品国产免费久久| 亚洲一区影音先锋| 国产乱理伦片在线观看夜一区| 欧美性大战久久久久久久蜜臀| 久久一二三国产| 亚洲福利视频一区二区| 成人午夜av影视| 精品国产百合女同互慰| 国产日韩欧美一区二区三区综合| 亚洲欧洲性图库| 蜜臀91精品一区二区三区 | 爽爽淫人综合网网站| 天堂久久一区二区三区| 欧美性猛交xxxxxx富婆| 国产精品久久久久久久久果冻传媒| 免费精品99久久国产综合精品| 色8久久精品久久久久久蜜| 久久理论电影网| 麻豆国产精品官网| 91精品国产福利在线观看| 一区二区三区四区中文字幕| av不卡一区二区三区| 国产亚洲精品bt天堂精选| 美女免费视频一区|