Snort Rules Management - srram

"Kevin Black" <[email protected]> Wed, 30 Oct 2002 08:57:00 -0800
Newsgroups gmane.comp.security.ids.snort.announce
Message-ID <[email protected]>
  I just wanted to let everyone know I have posted a rules 
management app to sourceforge: 
http://sourceforge.net/projects/srram/

This code will:
- if setup in cron will pull the latest signatures down 
nightly or weekly
- store the signatures in a database
- update only the signatures that have had their "rev" 
changed
- maintain rule and rule category state (enabled/disabled)
- export to a rule file only the enabled rules ignoring 
the disabled rules and rule categories.
- provides a, (soon to be better looking), web console to 
manage the enable/disable state

Once the console is used to enable and disable it is 
really not needed until the next time a rule needs to be 
disabled. These scripts can be used in conjunction with a 
scheduling process such as cron to automate the update of 
rules nightly, weekly, or whenever you like. It will not 
restart or HUP the snort daemon though, that is the users 
responsibility as of now as that makes me nervous :)

I am not a perl expert and one of the reasons for this 
beyond the obvious functionality is to improve my skills. 
I welcome any input, feedback, proposed changes, feature 
requests... etc... (Yes, I know the console looks ugly, I 
have only been interested in functionality up until now)

  - Kevin


-------------------------------------------------------
This sf.net email is sponsored by: Influence the future 
of Java(TM) technology. Join the Java Community 
Process(SM) (JCP(SM)) program now. 
http://ads.sourceforge.net/cgi-bin/redirect.pl?sunm0004en