Главная
Study mode:
on
1
Intro
2
Overview
3
WTF is a Next Gen Firewall?
4
Application Control
5
New Requirements
6
Application Detector Package
7
Applications
8
Examining Output
9
Intrusion Output
10
Application Rules
11
Writing a Rule
12
Custom Detector
13
Port Detection Example
14
Anatomy of a Detector
15
Information Header
16
Included Libraries
17
Detector PackageInfo
18
Initialization Function
19
Validation Function
20
Clean Function
21
Detection Functions
22
Other Detection Types
23
File APIs
24
File Inspection Preprocessor
25
Supported
26
snort.conf
27
File Type Identification
28
File Capture Alert
29
Clam-not-just-AV
Description:
Explore advanced Snort capabilities beyond traditional Intrusion Detection Systems in this 57-minute conference talk from BSides Columbus Ohio 2015. Delve into Next Generation Firewall concepts, Application Control, and File Control features. Learn about Application Detector Packages, examining output, writing custom rules, and creating detectors. Discover file inspection techniques, including file type identification and capture alerts. Gain insights into Snort's evolution as a comprehensive security tool, covering topics such as application APIs, preprocessing, and integration with antivirus solutions like ClamAV.

Snort Beyond IDS - Open Source Application and File Control

Add to list