May the source be with you, but remember the KISS principle ;-)
Home Switchboard Unix Administration Red Hat TCP/IP Networks Neoliberalism Toxic Managers
(slightly skeptical) Educational society promoting "Back to basics" movement against IT overcomplexity and  bastardization of classic Unix

Softpanorama Bookshelf:
Network Intrusion Detection Systems

News Softpanorama Reviews Managing Security with Snort and IDS Tools Snort 2.1 Intrusion Detection Snort Cookbook Snort: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID.  

Network IDS capabilities are overrated. Other things equal you can get more relevant information from firewall logs and, especially, from internal Unix server logs.  Still there are cases when there is a need to install them, be it political correctness or very specialized situation. The more specialized placement for the sensor the better are you changes for getting useful information instead of tons of false positives.  For example a sensor that is listing just for traffic directed at for DNS servers can get some useful information and probably even generate useful alerts, but a sensor that is listening to the whole traffic for the domain is less likely be able to get anything useful out of the traffic.

I think you should probably view Snort not as IDS where your return on the investment is minimal or negative but as a programmable traffic analyzer.  This is more constructive role for Snort and here some of the better books on Snort might make sense even without being discounted 50% or more :-) See also

There are a dozen books about Snort of varying quality (some with more baloney about intrusion detection, some with less). Most of them were published in 2003 or earlier when the level of paranoia was higher. A lot of them now look naive as they do not take into account that almost every server and desktop now has built-in firewall and the fact that traffic is directed to a certain port of the certain hos now mains nothing unless you understand the setting of the firewall on this particular host. Still as for monitoring traffic and detecting unusual traffic patterns they are sill useful:

  1. **** Managing Security with Snort and IDS Tools (Paperback). ISBN: 0596006616. This is a good book and it can serve as your first and major books on Snort. It has very good, well though out structure and it distills really important information.
  2. *** Snort 2.1 Intrusion Detection, Second Edition, ISBN: 1931836043. This is a reference-style book written by developers. Its only strong point is the spectrum of tools and issues discuss, but each is treated very briefly and somewhat superficially. It does not contain enough useful for implementer information or warns against pitfalls of  expecting from snort too much or the extremely low return on investment issues. As such it probably can serve only as a supplement, not the main book. The strong point of the book is that it references various  additional tools that are useful with Snort. Also as it comes from developers there is some useful info bout internals.
  3. *** Snort Cookbook (Paperback). ISBN: 0596007914. This is just a cookbook. Nothing special. Some information is useful, most is trivial, some is redundant.  Needs to be discounted more then 50% to provide any value.
  4. *** Snort: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID.  This is more a marginal book; more like short reference  then a tutorial. Still it contain some valuable information. PDF is avaible for free from the publisher 0131407333
  5. The Tao of Network Security Monitoring : Beyond Intrusion Detection (Paperback), ISBN: 0321246772

Dr. Nikolai Bezroukov

Search Amazon by keywords:

 You can use Honor System to make a contribution, supporting this site

Softpanorama Reviews

Managing Security with Snort and IDS Tools

Example in Chapter 7 (XSS attack signature) is very bad and actually demonstrated typical misunderstanding of the role of snort: attempt to use it as higher level protocols analyzer.


Old News ;-)


Network Intrusion Detection, 3/E

Stephen Northcutt
Judy Novak

ISBN: 0-7357-1265-4
Publisher: Sams
Copyright: 2003
Format: Paper; 512 pp

Our Price: $45.00
Status: Instock
Published: 08/27/2002


The Chief Information Warfare Officer for the entire United States teaches you how to protect your corporate network. This book is a training aid and reference for intrusion detection analysts. While the authors refer to research and theory, they focus their attention on providing practical information. The authors are literally the most recognized names in this specialized field, with unparalleled experience in defending our country's government and military computer networks. New to this edition is coverage of packet dissection, IP datagram fields, forensics, and snort filters.

Table Of Contents
(NOTE: Each chapter concludes with a Summary.)


1. IP Concepts.

The TCP/IP Internet Model. Packaging (Beyond Paper or Plastic). Addresses. Service Ports. IP Protocols. Domain Name System. Routing: How You Get There from Here.

2. Introduction to TCPdump and TCP.

TCPdump. Introduction to TCP. TCP Gone Awry.

3. Fragmentation.

Theory of Fragmentation. Malicious Fragmentation.

4. ICMP.

ICMP Theory. Mapping Techniques. Normal ICMP Activity. Malicious ICMP Activity. To Block or Not to Block.

5. Stimulus and Response.

The Expected. Protocol Benders. Abnormal Stimuli.

6. DNS.

Back to Basics: DNS Theory. Using DNS for Reconnaissance. Tainting DNS Responses.


7. Packet Dissection Using TCPdump.

Why Learn to Do Packet Dissection? Sidestep DNS Queries. Introduction to Packet Dissection Using TCPdump. Where Does the IP Stop and the Embedded Protocol Begin? Other Length Fields. Increasing the Snaplen. Dissecting the Whole Packet. Freeware Tools for Packet Dissection.

8. Examining IP Header Fields.

Insertion and Evasion Attacks. IP Header Fields. The More Fragments (MF) Flag.

9. Examining Embedded Protocol Header Fields.


10. Real-World Analysis.

You've Been Hacked! Netbus Scan. How Slow Can you Go? RingZero Worm.

11. Mystery Traffic.

The Event in a Nutshell. The Traffic. DDoS or Scan. Fingerprinting Participant Hosts.


12. Writing TCPdump Filters.

The Mechanics of Writing TCPdump Filters. Bit Masking. TCPdump IP Filters. TCPdump UDP Filters. TCPdump TCP Filters.

13. Introduction to Snort and Snort Rules.

An Overview of Running Snort. Snort Rules.

14. Snort Rules-Part II.

Format of Snort Options. Rule Options. Putting It All Together.


15. Mitnick Attack.

Exploiting TCP. Detecting the Mitnick Attack. Network-Based Intrusion-Detection Systems. Host-Based Intrusion-Detection Systems. Preventing the Mitnick Attack.

16. Architectural Issues.

Events of Interest. Limits to Observation. Low-Hanging Fruit Paradigm. Human Factors Limit Detects. Severity. Countermeasures. Calculating Severity. Sensor Placement. Outside Firewall. Push/Pull. Analyst Console. Host- or Network-Based Intrusion Detection.

17. Organizational Issues.

Organizational Security Model. Defining Risk. Risk. Defining the Threat. Risk Management Is Dollar Driven. How Risky Is a Risk?

18. Automated and Manual Response.

Automated Response. Honeypot. Manual Response.

19. Business Case for Intrusion Detection.

Part One: Management Issues. Part Two: Threats and Vulnerabilities. Part Three: Tradeoffs and Recommended Solution. Repeat the Executive

20. Future Directions.

Increasing Threat. Defending Against the Threat. Defense in Depth. Emerging Techniques.


Appendix A. Exploits and Scans to Apply Exploits.

False Positives. IMAP Exploits. Scans to Apply Exploits. Single Exploit, Portmap. Summary.

Appendix B. Denial of Service.

Brute-Force Denial-of-Service Traces. Elegant Kills. nmap. Distributed Denial-of-Service Attacks. Summary.

Appendix Ctection of Intelligence Gathering.

Network and Host Mapping. NetBIOS-Specific Traces. Stealth Attacks. Measuring Response Time. Worms as Information Gatherers. Summary.


The Tao of Network Security Monitoring Beyond Intrusion Detection

by Richard Bejtlich

Anton Chuvakin rated it high, so it is probably junk :-)

Snort for Dummies

by Charlie Scott, Paul Wolfe, Bert Hayes

I can understand the desire to write the book about Snort. What I cannot understand is why dummies need Snort.

Slashdot Three Snort Books Reviewed This guy looks like an amateur...

Eric Stats writes "Working as a Network Engineer for web-hosting company that prides itself on uptime and network availability, and moonlighting as a part-time Linux administrator, my managers and clients are starting to expect a level of information security knowledge from me. I decided that if I wanted to take my career to the next level, I needed to develop some security-specific skills. I heard a lot about the open source Intrusion Detection System (IDS), Snort from friends and co-workers (mostly that it was a pain to get running, and an even bigger pain to understand what it was doing)." To get past those frustrations, Eric looked at two more books on Snort (and compares them to the already-reviewed Intrusion Detection with Snort ); read on below for his take on what each offers.

I ran Snort at home for a while, using the online docs, but I could never get a handle on which output plugin to use (When to log? When to alert?), how to email alerts to myself (I later found out Snort doesn't natively do this), and how to create signatures from packet captures (no online docs at all for this). When I did get The Pig running, it filled up my log directory with thousands of small alert files, which ended up being in tcpdump format. This frustrated the hell out of me, so I decided I needed to find a good book on Snort, as the online docs simply did not describe how to use Snort from start to finish.

In the past few months, an assortment of books have come out on Snort. Because it has begun to eclipse closed-source, multimillion dollar IDSes in terms of raw performance and features, much attention is currently focused on Snort. Naturally, when an open source project achieves this level of notoriety, publishers, venture capitalists, and corporations want to get in on the game. The flood of Snort books is a testament to this, but it doesn't mean they were all created equally. This book review covers the three books on Snort currently available (we will see another two Snort books later this winter). It covers what is good about them, what is bad, and who the target audience is for each. If you are looking to learn intrusion detection the open source way, or simply do not have a million-dollar IT security budget, these books are a good starting point.

Each of these three books serves a different purpose and consequently is appropriate for a different reader. In summary, Rafeeq Rehman's Intrusion Detection with Snort: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID presents a concise, quick-start guidebook to getting Snort up and running fast. He doesn't delve into the details of Snort, and this book makes a perfect choice for a reader who wants to get The Pig up and running quickly and move on to something else.

The whole gaggle of authors that put together Snort 2.0 Intrusion Detection created a much-needed user manual for Snort. This book makes for good desktop reference, but assumes you understand the core concepts of intrusion detection, or have significant field experience with Snort. It is also somewhat convoluted to read; I suppose it's inevitable when you have 12 authors working on a single book, it is going to come out somewhat disjointed and jumbled. If I hadn't read the other two books first, I doubt I would have been able to piece together what this book is talking about in places. (Such as referring to Barnyard logs in one chapter and "unified binary format" in another; how is the reader going to know they are the same?)

Lastly, Jack Koziol's Intrusion Detection with Snort is a guidebook for using Snort in the real world, either on small networks or in large corporate settings. Like any security tool, Snort is only as effective as its operator. Snort can do an enormous number of things, but if you don't understand the "how and why" you aren't going to be able to apply your knowledge in unexpected, different, or new situations. Koziol's book bridges the gap and teaches you the nitty-gritty Snort details not found in online docs, as well as how to apply your newfound IDS knowledge in practice. This book does lack in terms of screenshots and diagrams, which can be frustrating at points. Instead of a paragraph of text, a simple diagram would have sufficed.

I first picked up Rehman's Intrusion Detection with Snort: Advanced IDS Techniques Using SNORT, Apache, MySQL, PHP, and ACID. Rehman's book is also a member of the Bruce Perens Open Source Series. All of the books in his series are published under the OPL. Overall, Rehman's book served as a good intro to Snort. I followed the examples, used some of the custom startup and log-rotation scripts, and got Snort working for the first time. I also learned of ACID, which is a PHP-based GUI for Snort, put out by Carnegie Mellon's CERT/CC. It makes managing alerts from Snort much less time-intensive. It was an exciting experience, but the book left me in the dark on a number of concepts that I knew I needed to learn. I still didn't understand what I was getting out of Snort; I had so many alerts I couldn't "tune out the noise." I didn't know when to use log or alert plugins, so I just turned on both for safety's sake. I also found that Snort was dropping packets (meaning it wasn't able to keep up with the traffic load going to my webservers hosted at home), but didn't find any way to fix this problem. This setup was fine for experimenting at home, but I didn't feel I would be able to use Snort in a mission-critical corporate setting yet.

I thumbed through Jack Koziol's Intrusion Detection with Snort at the bookstore, and it seemed to have some more detailed descriptions of using Snort. It also had a lot of the planning, deployment, and maintenance activities you never think of until you are faced with one at 2 a.m. (such as how to upgrade Snort in an organized manner after a vicious integer overflow exploit is released for a core Snort component). It is also the most popular Snort book, so I figured I would buy it. When I took it home, I learned where to place Snort on a network, and what advantages and disadvantages there are to different IDS sensor placement strategies, something I had never considered.

Koziol's book also had the technical detail I was in desperate need of. I learned how to use Barnyard to spool alerts, which keeps Snort from dropping packets. I got to write my own attack signatures from scratch by using Ethereal packet captures in an controlled lab environment. I created a targeted ruleset; it enables specific attack signatures based on what I actually have running on my network, simply using nmap and some complicated perl scripts. The targeted ruleset went a long way to reducing false alerts, and is now a selling product from the Snort commercial vendor, Sourcefire. I finally got email alerts working using syslog-ng with Snort. The book ends with some more advanced content, namely using Snort as an Intrusion Prevention device. You can setup Snort to block packets that match a signature, using Inline Snort, or you can have Snort reconfigure routers and firewalls to block offending IP addresses, using SnortSam. I've experimented with Inline Snort as part of a honeypot, but, as the author points out, this is not yet production-safe, as it can easily be used by attackers to disrupt network availability.

The final Snort book in this review is Snort 2.0 Intrusion Detection. This book has a lot of the screenshots and figures that the Koziol and Rehman books leaves out. It also contains a lot of useful diagrams, about one for every other page, and a CD-ROM with all of the Snort source and a pdf version of the book. This book, and the Koziol book, cover Snort version 2.0, which isn't all that much different from version 1.9 covered in the Rehman book. Still, it is nice to have the most up-to-date documentation, but it doesn't make the Rehman book any less effective. This book has the most reference material in it, over 500 pages' worth, and it has very organized user manual-like descriptions of important Snort components (preprocessors, output plugins, and rules). Keep in mind that this book was created more as a user manual rather than an implementer's guide. You aren't going to see planning, deployment, and maintenance activities as well as technical deployment examples, as in the Koziol book. And, you aren't going to find a concise quick-start guide such as the Rehman book.

In summary, you aren't going to find anything in this book that isn't in the other two. What you will find is lengthy descriptions, and a lot more screenshots. As stated before, Snort 2.0 Intrusion Detection was written by 12 different people (one of them a Sourcefire employee and website maintainer, Brian Caswell). This is obviously done by the publisher to get the book out as fast as possible, which is important for technology book publishers as books are outdated quickly, but has the end result of a disjointed book that contradicts itself in many areas. An example: one author stresses how deadly important it is for us to only use the latest Snort version, while another tells us to use the CDROM that comes with the book, which contains an outdated version of Snort.

You can clearly tell a different authors worked on different chapters, as the style and format change frequently. You can also tell that the authors didn't talk to each other much, as you will find one author referring to something in one chapter (unified binary format) that he expected to have been explained in a previous chapter. In print, the concept was not explained until later, which can be really frustrating if you are not a Snort pro. Additionally, there are enough grammatical errors in the book to be distracting, and, much like a vendor-provided user manual, the chapters don't logically flow from one to the next. If you do purchase this book, this slashdotter would recommend it as a supplement to either the Rehman or Koziol book.

Slashdot Three Snort Books Reviewed

don't buy use safari

(Score:5, Interesting) by asv108 (141455) <> on Wednesday August 13, @02:16PM (#6688148)
( | Last Journal: Friday January 21, @02:42PM)

I wasn't a big fan of the online book idea until I tried Safari [] for the first time a few months ago. A quick search for snort reveals 38 different books that focus on or have chapters dealing with snort, included the one book "Intrusion Detection with Snort" that was mentioned in this review. The retail cost of these three books alone would cover a safari subscription for a year (10 books out at any given time). There is a free 14 day trial [], it got me hooked. I ended up selling 20+ books in my bookshelf that were already on Safari, covering my Safari fees for the next 2 years.



Groupthink : Two Party System as Polyarchy : Corruption of Regulators : Bureaucracies : Understanding Micromanagers and Control Freaks : Toxic Managers :   Harvard Mafia : Diplomatic Communication : Surviving a Bad Performance Review : Insufficient Retirement Funds as Immanent Problem of Neoliberal Regime : PseudoScience : Who Rules America : Neoliberalism  : The Iron Law of Oligarchy : Libertarian Philosophy


War and Peace : Skeptical Finance : John Kenneth Galbraith :Talleyrand : Oscar Wilde : Otto Von Bismarck : Keynes : George Carlin : Skeptics : Propaganda  : SE quotes : Language Design and Programming Quotes : Random IT-related quotesSomerset Maugham : Marcus Aurelius : Kurt Vonnegut : Eric Hoffer : Winston Churchill : Napoleon Bonaparte : Ambrose BierceBernard Shaw : Mark Twain Quotes


Vol 25, No.12 (December, 2013) Rational Fools vs. Efficient Crooks The efficient markets hypothesis : Political Skeptic Bulletin, 2013 : Unemployment Bulletin, 2010 :  Vol 23, No.10 (October, 2011) An observation about corporate security departments : Slightly Skeptical Euromaydan Chronicles, June 2014 : Greenspan legacy bulletin, 2008 : Vol 25, No.10 (October, 2013) Cryptolocker Trojan (Win32/Crilock.A) : Vol 25, No.08 (August, 2013) Cloud providers as intelligence collection hubs : Financial Humor Bulletin, 2010 : Inequality Bulletin, 2009 : Financial Humor Bulletin, 2008 : Copyleft Problems Bulletin, 2004 : Financial Humor Bulletin, 2011 : Energy Bulletin, 2010 : Malware Protection Bulletin, 2010 : Vol 26, No.1 (January, 2013) Object-Oriented Cult : Political Skeptic Bulletin, 2011 : Vol 23, No.11 (November, 2011) Softpanorama classification of sysadmin horror stories : Vol 25, No.05 (May, 2013) Corporate bullshit as a communication method  : Vol 25, No.06 (June, 2013) A Note on the Relationship of Brooks Law and Conway Law


Fifty glorious years (1950-2000): the triumph of the US computer engineering : Donald Knuth : TAoCP and its Influence of Computer Science : Richard Stallman : Linus Torvalds  : Larry Wall  : John K. Ousterhout : CTSS : Multix OS Unix History : Unix shell history : VI editor : History of pipes concept : Solaris : MS DOSProgramming Languages History : PL/1 : Simula 67 : C : History of GCC developmentScripting Languages : Perl history   : OS History : Mail : DNS : SSH : CPU Instruction Sets : SPARC systems 1987-2006 : Norton Commander : Norton Utilities : Norton Ghost : Frontpage history : Malware Defense History : GNU Screen : OSS early history

Classic books:

The Peter Principle : Parkinson Law : 1984 : The Mythical Man-MonthHow to Solve It by George Polya : The Art of Computer Programming : The Elements of Programming Style : The Unix Hater�s Handbook : The Jargon file : The True Believer : Programming Pearls : The Good Soldier Svejk : The Power Elite

Most popular humor pages:

Manifest of the Softpanorama IT Slacker Society : Ten Commandments of the IT Slackers Society : Computer Humor Collection : BSD Logo Story : The Cuckoo's Egg : IT Slang : C++ Humor : ARE YOU A BBS ADDICT? : The Perl Purity Test : Object oriented programmers of all nations : Financial Humor : Financial Humor Bulletin, 2008 : Financial Humor Bulletin, 2010 : The Most Comprehensive Collection of Editor-related Humor : Programming Language Humor : Goldman Sachs related humor : Greenspan humor : C Humor : Scripting Humor : Real Programmers Humor : Web Humor : GPL-related Humor : OFM Humor : Politically Incorrect Humor : IDS Humor : "Linux Sucks" Humor : Russian Musical Humor : Best Russian Programmer Humor : Microsoft plans to buy Catholic Church : Richard Stallman Related Humor : Admin Humor : Perl-related Humor : Linus Torvalds Related humor : PseudoScience Related Humor : Networking Humor : Shell Humor : Financial Humor Bulletin, 2011 : Financial Humor Bulletin, 2012 : Financial Humor Bulletin, 2013 : Java Humor : Software Engineering Humor : Sun Solaris Related Humor : Education Humor : IBM Humor : Assembler-related Humor : VIM Humor : Computer Viruses Humor : Bright tomorrow is rescheduled to a day after tomorrow : Classic Computer Humor

The Last but not Least Technology is dominated by two types of people: those who understand what they do not manage and those who manage what they do not understand ~Archibald Putt. Ph.D

Copyright � 1996-2021 by Softpanorama Society. was initially created as a service to the (now defunct) UN Sustainable Development Networking Programme (SDNP) without any remuneration. This document is an industrial compilation designed and created exclusively for educational use and is distributed under the Softpanorama Content License. Original materials copyright belong to respective owners. Quotes are made for educational purposes only in compliance with the fair use doctrine.

FAIR USE NOTICE This site contains copyrighted material the use of which has not always been specifically authorized by the copyright owner. We are making such material available to advance understanding of computer science, IT technology, economic, scientific, and social issues. We believe this constitutes a 'fair use' of any such copyrighted material as provided by section 107 of the US Copyright Law according to which such material can be distributed without profit exclusively for research and educational purposes.

This is a Spartan WHYFF (We Help You For Free) site written by people for whom English is not a native language. Grammar and spelling errors should be expected. The site contain some broken links as it develops like a living tree...

You can use PayPal to to buy a cup of coffee for authors of this site


The statements, views and opinions presented on this web page are those of the author (or referenced source) and are not endorsed by, nor do they necessarily reflect, the opinions of the Softpanorama society. We do not warrant the correctness of the information provided or its fitness for any purpose. The site uses AdSense so you need to be aware of Google privacy policy. You you do not want to be tracked by Google please disable Javascript for this site. This site is perfectly usable without Javascript.

Last modified: March 12, 2019