Chapter one is a very simple
introduction to intrusion detection and
Snort. Beginning with a brief look at topology, chapter
two runs
through an installation of Snort, but does not provide
much in the way
of explanation or recommendation at the various points.
The coverage
of Snort rule creation and syntax, in chapter three, is
clear and
reasonable, but could use more examples of malicious packets
and how
they might be identified. Chapter four does explain some
exploit
rules, in discussing preprocessors, but briefly, and then
goes on to
output options. Chapters five, six, and seven describe
MySQL, ACID
(Analysis Console for Intrusion Databases), and other tools
for using
Snort in conjunction with collected information.
This is a decent printed documentation for the system,
but not much
more.
copyright Robert M. Slade, 2003 BKIDWSAI.RVW 20030902
|