TAILIEUCHUNG - Open Source Security Tools : Practical Guide to Security Applications part 24

Open Source Security Tools : Practical Guide to Security Applications part 24. Few frontline system administrators can afford to spend all day worrying about security. But in this age of widespread virus infections, worms, and digital attacks, no one can afford to neglect network defenses. Written with the harried IT manager in mind, Open Source Security Tools is a practical, hands-on introduction to open source security tools. | Page 209 Thursday June 24 2004 12 17 PM Configuring Snort for Maximum Performance 209 Syslog For UNIX Linux systems you should use the following directive output alert_syslog LOG_AUTH LOG_ALERT For Windows system you can use any of the following formats output alert_syslog LOG_AUTH LOG_ALERT output alert_syslog host hostname LOG_AUTH LOG_ALERT output alert_syslog host hostname port LOG_AUTH LOG_ALERT where hostname and port are the IP address and port of your Syslog server. Database The general format for configuring database output is output database log database_type user user_name password password dbname dbname host database_address where you replace database_type with one of the valid databases for Snort MySQL postgresql unixodbc or mssql . You also replace user_name with a valid user name on the database box and password with the appropriate password. The dbname variable identifies the name of the database to log to. Finally database_address is the IP address of your database server. It is not recommended that you try to run Snort and your database on the same server. In addition to being more secure to have your alert data on another box Snort and a database running on the same machine will slow down performance considerably. While database configuration is not the subject of this book the basic configuration of a MySQL database for Snort and other programs is discussed in Chapter 8. Unified This is a basic binary format for quick logging and storage for future use. The two arguments that are supported are filename and limi t. Here is the format output alert_unified filename limit 128 5. Customize your rule sets. You can fine-tune Snort by adding or deleting rule sets. The file lets you add or delete entire classes of rules. At the bottom of the file you will see all the alert rule sets listed. You can turn off a whole category of rules by commenting out that line by putting a sign at the beginning. For example you .

TỪ KHÓA LIÊN QUAN
TAILIEUCHUNG - Chia sẻ tài liệu không giới hạn
Địa chỉ : 444 Hoang Hoa Tham, Hanoi, Viet Nam
Website : tailieuchung.com
Email : tailieuchung20@gmail.com
Tailieuchung.com là thư viện tài liệu trực tuyến, nơi chia sẽ trao đổi hàng triệu tài liệu như luận văn đồ án, sách, giáo trình, đề thi.
Chúng tôi không chịu trách nhiệm liên quan đến các vấn đề bản quyền nội dung tài liệu được thành viên tự nguyện đăng tải lên, nếu phát hiện thấy tài liệu xấu hoặc tài liệu có bản quyền xin hãy email cho chúng tôi.
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.