Snort Rules Management - srram
"Kevin Black" <[email protected]> Wed, 30 Oct 2002 08:57:00 -0800
| Newsgroups | gmane.comp.security.ids.snort.announce |
|---|---|
| Message-ID | <[email protected]> |
I just wanted to let everyone know I have posted a rules management app to sourceforge: http://sourceforge.net/projects/srram/ This code will: - if setup in cron will pull the latest signatures down nightly or weekly - store the signatures in a database - update only the signatures that have had their "rev" changed - maintain rule and rule category state (enabled/disabled) - export to a rule file only the enabled rules ignoring the disabled rules and rule categories. - provides a, (soon to be better looking), web console to manage the enable/disable state Once the console is used to enable and disable it is really not needed until the next time a rule needs to be disabled. These scripts can be used in conjunction with a scheduling process such as cron to automate the update of rules nightly, weekly, or whenever you like. It will not restart or HUP the snort daemon though, that is the users responsibility as of now as that makes me nervous :) I am not a perl expert and one of the reasons for this beyond the obvious functionality is to improve my skills. I welcome any input, feedback, proposed changes, feature requests... etc... (Yes, I know the console looks ugly, I have only been interested in functionality up until now) - Kevin ------------------------------------------------------- This sf.net email is sponsored by: Influence the future of Java(TM) technology. Join the Java Community Process(SM) (JCP(SM)) program now. http://ads.sourceforge.net/cgi-bin/redirect.pl?sunm0004en