TY - GEN
T1 - LASSP
T2 - 6th International Conference on Emerging Technologies, ICET 2010
AU - Hafeez, Khalid
AU - Masood, Muddassar
AU - Malik, Owais
AU - Anwar, Zahid
PY - 2010
Y1 - 2010
N2 - Snort, an intrusion detection/prevention system (IDS/IPS), performs protocol analysis, content searching/matching, and is commonly used to actively block or passively detect a variety of attacks and probes. When snort is running in intrusion detection mode, it allows the user to analyze network traffic against s user defined set of rules. A rich set of rules is easily available which allows a non-expert of security to use snort for his network protection with a false sense of confidence. Snort rules are quite large in size and number thus adding or deleting rules without a proper understanding may lead to an unsecure environment. Moreover enabling all rules in the list in snort configuration might enable security but can cause severe performance degradation. We have developed a system that infers security and performance levels of snort by analyzing its configuration and the snort rules that are enabled. This system may facilitate a non-expert of security to automatically tweak the security and performance levels of his network and to configure it according to the organizational policy.
AB - Snort, an intrusion detection/prevention system (IDS/IPS), performs protocol analysis, content searching/matching, and is commonly used to actively block or passively detect a variety of attacks and probes. When snort is running in intrusion detection mode, it allows the user to analyze network traffic against s user defined set of rules. A rich set of rules is easily available which allows a non-expert of security to use snort for his network protection with a false sense of confidence. Snort rules are quite large in size and number thus adding or deleting rules without a proper understanding may lead to an unsecure environment. Moreover enabling all rules in the list in snort configuration might enable security but can cause severe performance degradation. We have developed a system that infers security and performance levels of snort by analyzing its configuration and the snort rules that are enabled. This system may facilitate a non-expert of security to automatically tweak the security and performance levels of his network and to configure it according to the organizational policy.
UR - https://www.scopus.com/pages/publications/78650392230
U2 - 10.1109/ICET.2010.5638483
DO - 10.1109/ICET.2010.5638483
M3 - Conference contribution
AN - SCOPUS:78650392230
SN - 9781424480586
T3 - Proceedings - 2010 6th International Conference on Emerging Technologies, ICET 2010
SP - 240
EP - 245
BT - Proceedings - 2010 6th International Conference on Emerging Technologies, ICET 2010
Y2 - 18 October 2010 through 19 October 2010
ER -