Snort
Snortは、自由でオープンソースのネットワーク侵入検知システム(IDS)、侵入防止システム(IPS)である[3]。ソー…
| 開発元 | シスコシステムズ | ||
|---|---|---|---|
| 最新版 |
| ||
| リポジトリ | |||
| プログラミング 言語 | C++ (since version 3.0) | ||
| 対応OS | Cross-platform[2] | ||
| サポート状況 | サポート中 | ||
| 種別 |
| ||
| ライセンス | GNU General Public License | ||
| 公式サイト |
www |
Snortは、自由でオープンソースのネットワーク侵入検知システム(IDS)、侵入防止システム(IPS)である[3]。ソースファイアの創業者であるMartin Roeschによって1998年に開発された[4][5]。ソースファイアはシスコシステムズが2013年に買収したため、現在は同社が開発を進めている[6][7][8]。
2009年、SnortはInfoWorldの「オープンソースの殿堂」に選ばれた[9]。
使用法
Snortのネットワークベース侵入検知システム(IDS/IPS)はInternet Protocolの通信において、リアルタイムでのトラフィック解析とパケットのロギングをすることができる。プロトコルの解析、パケットのデータのマッチングなどを行う。
また、OSフィンガープリンティング、セマンティックURL攻撃、バッファオーバーフロー、server message blockの探索 、ステルスポートスキャンなどの攻撃や探索を検知するために使うこともできる[10]。
Snortは以下の3種類のメインモードが設定できる。
- Snifferモード
- Packet Loggerモード
- ネットワーク侵入検知モード
Snifferモード
ネットワーク上のパケットを読み取り、コンソールに表示する。
Packet Loggerモード
このモードでは、パケットのログをディスク上に保存する。
ネットワーク侵入検知(NIDS)モード
侵入検知モードでは、ネットワークのトラフィックを監視し、ユーザーの設定したルールに照らし合わせて解析する。その結果に従って、ある特定の操作を行う[11]。
サードパーティーのツール
Snortのインターフェースとして、システム管理やパフォーマンス・ログの解析を行うツールがいくつか存在する。
- Snorby - Ruby on Railsによって開発されたGPLv3[12]のアプリケーション
- BASE
- Sguil (free)
関連項目
脚注
- ^ “Release 3.12.2.0” (2026年4月23日). 2026年4月24日閲覧。
- ^ “Snort - Network Intrusion Detection & Prevention System”. snort.org. 2026年5月16日閲覧。
- ^ Jeffrey Carr (2007年6月5日). “Snort: Open Source Network Intrusion Prevention”. 2010年6月23日閲覧。
- ^ Larry Greenemeier (2006年4月25日). “Sourcefire Has Big Plans For Open-Source Snort”. 2010年6月23日閲覧。
- ^ eWeek.com Staff (2008年4月4日). “100 Most Influential People in IT”. 2010年6月23日閲覧。
- ^ “Cisco Completes Acquisition of Sourcefire”. Cisco Systems (2013年10月7日). 2020年4月13日閲覧。
- ^ “Cisco to Buy Sourcefire, a Cybersecurity Company, for $2.7 Billion”. The New York Times. 2013年7月23日閲覧.
- ^ “Snort: The World’s Most Widely Deployed IPS Technology” (英語). Cisco. 2018年8月30日閲覧。
- ^ Doug Dineley (2009年8月17日). “The greatest open source software of all time”. 2020年4月13日閲覧。
- ^ James Stanger (2011). How to Cheat at Securing Linux. Burlington, MA: Elsevier. p. 126. ISBN 978-0-08-055868-4
- ^ The Snort Project. “1.4 Network Intrusion Detection System Mode”. 2024年3月9日閲覧。
- ^ “snorby / LICENSE”. GitHub (2013年). 2021年1月19日閲覧。
外部リンク
Content Disclaimer
Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.
- The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
- There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
- It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
- Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
- Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.