Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 1.10 Can Snort be Up: 1 Background Previous: 1.8 I'm on a

1.9 Is Snort vulnerable to IDS noise generators like ``Stick'' and ``Snot''?

It is now possible to defeat these kinds of noise generators with the stream4 preprocessor (see (see FAQ [*])). Even without the stream4 preprocessor enabled, Snort will weather the alert storm without falling over or losing a lot of alerts due to its highly optimized nature. Using tools that generate huge amounts of alerts will warn a good analyst that someone is trying to sneak by their defenses.



Nigel Houghton 2006-10-02