|
|
|
|
Snort Forums Archive
Archive Home » Snort Newbies » Snort Vs. Cisco
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
Snort Vs. Cisco
Posted by PRYBAR on March 09, 2005 07:27:08
Hello.
I'm rather new to IDS, however I have been charged with learning it to support my company's existing Cisco IDS infrastructre. I'll have to say that I find the Cisco product fairly cumbersome to use. Currently we have about 14 sensors, so my questions are these:
What advantages/disadvantages does Snort have compared to the Cisco product?
I have followed the setup guide and been able to get a functioning Snort box with the Acid console. Is there a way to integrate the Cisco sensors into this?
Thanks
PRYBAR |
|
Posted by roesch on March 10, 2005 04:45:09
Hi Prybar,
ACID doesn't work with Cisco IDS at all. You might want to check out OSSIM (http://www.ossim.net), it
might be able to work for you. Cisco's IDS is probably one of the worst ones out there from a user
experience standpoint, any chance you can go with something decent?
Oh, advantages/disadvantages vs Snort. This is just my opinion of course, I have had recent exposure
to their product.
Advantages: It comes from Cisco and your managers won't get fired for using Cisco.
Disadvantages: Black box design, you'll have no idea why it does anything that it does. Awful GUI (well,
3 of them), apparently designed in the 9th ring of the Inferno. You could argue that Snort at the
command line + vi is a better GUI. Closed signature language, you have no ability to see what or how
they're trying to detect anything. Signatures focused on detecting mostly exploits, small changes to
exploits will evade them. Dated design, their intrusion detection engine doesn't appear to have
improved in any significant way in years. Difficult to install. Difficult to administer. Requires external
data management infrastructure to be usable in any but the smallest environments (Sourcefire builds in
enterprise IDS data management). I could go on.
-Marty |
|
|
|
|
|