fwsnort
Details
| Size: | 156K |
| Last Update: | 2008-07-03 21:08:54 |
| Version: | 0.8.1 |
| OS Support: | Linux |
| License/Program Type: | GPL (GNU General Public License) |
| Publisher: | Michael Rash |
| Price: | $0.00 |
Description:
fwsnort 0.8.1 is logging software developed by Michael Rash.
fwsnort parses the rules files included in the snort intrusion detection system and builds an equivalent iptables ruleset for as many rules as possible.
fwsnort accepts command line arguments to restrict processing to any particular class of snort rules such as "ddos", "backdoor", or "web-attacks". Processing can even be restricted to a specific snort rule as identified by its "snort id" or "sid".
fwsnort utilizes the iptables string match module (together with a custom patch that adds a --hex-string option to the iptables user space code) to detect application level signatures.
fwsnort (optionally) makes use of the IPTables::Parse module (to be submitted to CPAN) to translate snort rules for which matching traffic could potentially be passed through the existing iptables ruleset.
Here are some key features of "fwsnort":
Detection for tcp syn, fin, null, and xmas scans as well as udp scans.
Detection of many signature rules from the snort intrusion detection system.
Forensics mode iptables logfile analysis (useful as a forensics tool for extracting scan information from old iptables logfiles).
Passive operating system fingerprinting via tcp syn packets. Two different fingerprinting strategies are supported; a re-implementation of p0f that strictly uses iptables log messages (requires the --log-tcp-options command line switch), and a TOS-based strategy.
Email alerts that contain tcp/udp/icmp scan characteristics, reverse dns and whois information, snort rule matches, remote OS guess information, and more.
Content-based alerts for buffer overflow attacks, suspicious application commands, and other suspect traffic through the use of the iptables string match extension and fwsnort.
Icmp type and code header field validation.
Configurable scan thresholds and danger level assignments.
Iptables ruleset parsing to verify "default drop" policy stance.
IP/network danger level auto-assignment (can be used to ignore or automatically escalate danger levels for certain networks).
DShield alerts.
Auto-blocking of scanning IP addresses via iptables and/or tcpwrappers based on scan danger level. (This is NOT enabled by default.)
Status mode that displays a summary of current scan information with associated packet counts, iptables chains, and danger levels.
What's New in This Release:
Updated to use the string match extension "--algo bm" argument if fwsnort is being run on a 2.6.14 (or greater) kernel.
Updated to handle the Snort "offset" and "depth" keywords via the --from and --to options to the string match extension in the 2.6.14 kernel.
An RPM package has been created.
There are minor man page updates.
fwsnort 0.8.1 supports different languages (including english). It works with Linux.
Downloading fwsnort 0.8.1 will take several seconds if you use fast ADSL connection.
0 comments
Add to
fwsnort Version History
Related Software
|
|
From category: Monitoring |
| TraffStats is a monitoring and traffic analysis application that uses SNMP to collect data from any enabled device.... |
|
|
From category: System-Administration |
| chngpwd 1.0.0 is system administration software developed by Raul Dias. chngpwd is a secure wrapper to change user passwords another user in a PAM-enabled system. chngpwd\'s main use is as a... |
|
|
From category: Benchmarks |
| Bootchart 0.9 is benchmarks software developed by Ziga Mahkovec. Bootchart is a software for performance analysis and visualization of the GNU/Linux boot process. Resource utilization and process... |
|
|
From category: Boot |
| Ext2 Filesystems Utilities 1.39 is boot software developed by Theodore Ts\'o. Ext2 Filesystem Utilities project (e2fsprogs) contain all of the standard utilities for creating, fixing, configuring ,... |
|
|
From category: System-Administration |
| Andutteye Software Suite 2.3 (Cache) is system administration software developed by Andutteye Software. Andutteye Software Suite is a systems management tool. Andutteye Software Suite has a modular... |
|
|
From category: Networking |
| Airhook 2 is networking software developed by Dan Egnor. Airhook is a transmission control and reliable data delivery protocol, like TCP. Unlike TCP, Airhook gracefully handles intermittent... |
|
|
From category: Networking |
| Firepass 1.1.2a is networking software developed by Alex Dyatlov. Firepass - is a tunneling tool, allowing to bypass firewall restrictions and encapsulate data flows inside legal ones to use HTTP P... |
|
|
From category: Networking |
| ASN RADIUS Admin 0.5 is networking software developed by Dawid Ci&281;&380;arkiewicz. ARA&039;s goal is to create simple but convenient solution for managing the FreeRADIUS server. ARA is... |
|
|
From category: Operating-Systems-Linux-Distri |
| CentOS 4.4 Server CD is operating systems linux distri software developed by CentOS Development Team. CentOS is an Enterprise-class Linux Distribution derived from sources freely provided to the pu... |
|
|
From category: Networking |
| The ATA over Ethernet Tools are intended for use in conjunction with an ATA over Ethernet (AoE) driver for a Linux 2.6 kernel.... |
|
|
From category: Networking |
| Balance 3.34 is networking software developed by Thomas Obermair. Balance is our suprisingly successful load balancing solution being a simple but powerful generic tcp proxy with round robin load b... |
|
|
From category: System-Administration |
| ChangePassword 0.9 is system administration software developed by Vinicius M. Souza. ChangePassword modifies the passwords of passwd, Samba, and Squid through the Web. All passwords are syncronized... |
|
|
From category: Diagnostics |
| cpuburn 1.4 is diagnostics software developed by Robert Redelmeier. WARNING: This program is designed to heavily load CPU chips. Undercooled, overclocked or otherwise weak systems may fail causi... |
|
|
From category: Operating-Systems |
| RESTORE is scalable to a complete backup solution for multiple workstations, servers, and data centers.... |
|
|
From category: System-Administration |
| cec 2 is system administration software developed by Ed Cashin at Coraid. cec (Coraid Ethernet Console) client, can connect to any CEC server over raw ethernet. Coraid appliances are examples of CE... |
Leave a comment