معلومات البرنامج fwsnort 0.9.0

مرات التنزيل
23
متطلبات التشغيل
الحجم 0
الترخيص
الاصدار 0
اضيف في
25/03/2007
اجمالي الاصوات
0
الموقع علي الانترنت
التقييم
0.0000
قيم هذا البرنامج

 
Description
fwsnort parses the rules files included in the snort intrusion detection system and builds an equivalent iptables ruleset for as many rules as possible.

fwsnort accepts command line arguments to restrict processing to any particular class of snort rules such as "ddos", "backdoor", or "web-attacks". Processing can even be restricted to a specific snort rule as identified by its "snort id" or "sid".

fwsnort utilizes the iptables string match module (together with a custom patch that adds a --hex-string option to the iptables user space code) to detect application level signatures.

fwsnort (optionally) makes use of the IPTables::Parse module (to be submitted to CPAN) to translate snort rules for which matching traffic could potentially be passed through the existing iptables ruleset.

Here are some key features of "fwsnort":
· Detection for tcp syn, fin, null, and xmas scans as well as udp scans.
· Detection of many signature rules from the snort intrusion detection system.
· Forensics mode iptables logfile analysis (useful as a forensics tool for extracting scan information from old iptables logfiles).
· Passive operating system fingerprinting via tcp syn packets. Two different fingerprinting strategies are supported; a re-implementation of p0f that strictly uses iptables log messages (requires the --log-tcp-options command line switch), and a TOS-based strategy.
· Email alerts that contain tcp/udp/icmp scan characteristics, reverse dns and whois information, snort rule matches, remote OS guess information, and more.
· Content-based alerts for buffer overflow attacks, suspicious application commands, and other suspect traffic through the use of the iptables string match extension and fwsnort.
· Icmp type and code header field validation.
· Configurable scan thresholds and danger level assignments.
· Iptables ruleset parsing to verify "default drop" policy stance.
· IP/network danger level auto-assignment (can be used to ignore or automatically escalate danger levels for certain networks).
· DShield alerts.
· Auto-blocking of scanning IP addresses via iptables and/or tcpwrappers based on scan danger level. (This is NOT enabled by default.)
· Status mode that displays a summary of current scan information with associated packet counts, iptables chains, and danger levels.

What's New in This Release:
· Support for multiple content matches was added, since this is supported by iptables.
· This increased the fwsnort translation rate by 10%, so about 60% of all Snort-2.3.3 rules can be translated now.
· Emulation was added for distance and within from previous content match based on --from and --to and the length of the previous pattern.
· The ability to include the Snort "msg", "classtype", "reference", "priority", and "rev" fields in each iptables rule with the comment match was added.
· This can be disabled with --no-ipt-comments.

 

الترجمة الالية للوصف

تنزيل fwsnort 0.9.0  Free Download fwsnort 0.9.0 تنزيل:   fwsnort 0.9.0
اخبر صديق fwsnort 0.9.0



أكثر البرامج تنزيلا في هذا القسم
LimeWire 4.12.11
Sound Converter 0.9.4
Get YouTube Video 1.3e
Subtitle Editor 0.13.4
Advanced Guestbook Script 2.4.2
Text::Emoticon 0.04
FlowPlayer 1.11
Javascript Flickr Slideshow 0.2
Jazz Radio 1.0.1.29
SMPlayer 0.4.19



اخترنا لك من البرامج المميزة
Gizmo for Windows 2.0.2.223 (Freeware)
Acoustica MP3 Audio Mixer 2.01يخلط و يسج ...
cinit 0.3pre2
Akram Audio Converter 5.0.108 (Demo)
Simple Photo Resizer 1.0.2479 (Freeware)
RSI-Shield 4.5.14.0 (Trial)
StockTreader
Utility Lock 1.0
WinGuard Pro 2004 5.7.1.5 beta
GroundWork Monitor Open Source 5.1.0 Alp ...
Mp3nity 1.3.001 (Trial)
SmartMorph 1.53
Absolute Sound Recorder 3.4.9 (Demo)
TV On PC Elite 2.1 (Freeware)
Falltime Rain Demo Screensaver 1.0 (Demo ...






البرنامج السابق : LilyPond 2.11.21-1 LilyPond 2.11.21-1 البرنامج التالي : xterm patch #225 xterm patch #225


بحث
fwsnort , parses , rules , files , included , snort , intrusion , detection , system , builds , equivalent , iptables , ruleset , many , rules , possible. , fwsnort , accepts , command , line , arguments , restrict , processing , particular , class , snort , rules , such , ddos ,

التصنيف:
Copyright (©) Moshax 2008. All rights reserved.