Snort FAQ
General
1. What is Snort?
2. What is open source?
3. Where can I download Snort?
4. What can I do with Snort?
5. What is the relationship between Snort and Sourcefire?
6. Does Sourcefire sell Snort?
7. What is a Snort Integrator?
8. What is the role of the Sourcefire Vulnerability Research Team (VRT)?
9. How do I submit questions about Snort?
Snort.org
1. What is a registered user?
2. Why do I need to register?
3. What if I do not wish to register?
4. Will my information be shared with any other parties or used for marketing?
5. How can I provide feedback or suggestions for the site?
6. How can I find a user group in my area?
7. What if there isn't a local group?
Rules
1. What is a Snort rule?
2. What is a signature?
3. What is a vulnerability?
4. What is an exploit?
5. What is a protocol?
6. What are Community Rules?
7. What are Sourcefire VRT Certified Rules?
8. What is a user-defined rule?
9. How are rules distributed?
Sourcefire VRT Subscription
1. What does the Sourcefire VRT subscription entitle me to?
2. Do I have to subscribe to receive Sourcefire VRT Rules?
3. How much does a subscription cost?
4. If I purchase a subscription, can I deploy the rules on more than one sensor?
5. Can I use tools such as Oinkmaster to manage the subscription?
Licensing
1. What is the GNU GPL?
2. What is the Sourcefire VRT Certified Rules License Agreement?
3. What is the Snort Integrator License from Sourcefire?
4. How is the Snort software licensed?
5. Why are the rules licensed separately from the software?
6. What license is used if I contribute code for the Snort Engine?
7. What license is used if I contribute a rule for Snort?
| General |
|---|
|
1. What is Snort? 2. What is open source? 3. Where can I download Snort? 4. What can I do with Snort? 5. What is the relationship between Snort and Sourcefire? 6. Does Sourcefire sell Snort? 7. What is a Snort Integrator? 8. What is the role of the Sourcefire Vulnerability Research Team™ (VRT)? 9. How do I submit questions about Snort? |
| Snort.org |
|---|
|
1. What is a registered user? 2. Why do I need to register? 3. What if I do not wish to register? 4. Will my information be shared with any other parties or used for marketing? 5. How can I provide feedback or suggestions for the site? 6. How can I find a user group in my area? 7. What if there isn't a local user group? |
| Rules |
|---|
|
1. What is a Snort Rule? 2. What is a signature? This type of detection is typically classified as day after detection, as actual public exploits are necessary for this type of detection to work. Anti-Virus companies utilize this type of technology for protecting their customers from virus outbreaks. As we have seen over the years this type of protection only has limited protection capabilities as the virus has already infected someone before a signatures can be written. 3. What is a vulnerability? The below is a modified version of Microsoft's definition of a vulnerability, written by Scott Culp. This definition allows are a wide range of things to be classified as vulnerabilities. It includes everything from the LSASS Buffer Overflow to characters flaws that allow for easy social engineering. This makes sense as vulnerabilities have been around since the beginning of time and have existed in every device or idea that was created to restrict or moderate access. 4. What is an exploit? 5. What is a protocol?
a.TCP 3-Way Handshake occurs. 6. What are Community Rules? 7. What are Sourcefire VRT Certified Rules? 8. What is a user-defined rule? 9. How are rules distributed?
a. Subscribers will receive rulesets in real-time as they are released to Sourcefire customers - 30 days ahead of registered users |
| Sourcefire Subscription | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
1. What does the Sourcefire VRT Certified Rules Subscription entitle me to? Subscribers receive:
2. Do I have to subscribe to receive Sourcefire VRT Rules? 3. How much does a Subscription cost?
4. If I purchase a subscription, can I deploy the rules on other sensors? 5. Can I use tools such as Oinkmaster to manage the subscription? |
| Licensing |
|---|
|
1. What is the GNU GPL? You can read the complete GPL license here. 2. What is the Sourcefire VRT Certified Rules License Agreement? View the complete Sourcefire VRT Certified Rules License Agreement. 3. What is the Snort Integrator License from Sourcefire? 4. How is the Snort Engine licensed? 5. Why are the rules licensed separately from the Engine? 8. What license is used if I contribute code for the Snort Engine? 9. What license is used if I contribute a rule for Snort? |
