[Snort-users] Viirus rules

Michael.Mulholland at ...9481... Michael.Mulholland at ...9481...
Mon Feb 2 01:04:01 EST 2004


Folks,

I'm using the IDS Policy Manager to download new rules and push them out to
a number of sensors but the virus set has a note claiming these rules are
not actively updated.

I'm relatively new to Snort so i'm not sure how i should keep my signatures
up-to-date with the large number of virus and other such attacks out there

Do i need to write my own signatures - if so where do i find the details on
what content to scan for?

many thanks to anyone who takes the time to read this and more so to those
who reply

michael mulholland
*******************************************************************************************

Any views expressed by the sender of this message are not necessarily those
of the Department of Finance & Personnel and the Office of the First
Minister and the Deputy First Minister.  This email and any files
transmitted with it are intended solely for the use of the individual or
entity to whom they are addressed.  If you have received this email in
error please notify the sender immediately by using the reply facility in
your email software.  All emails are swept for the presence of viruses.
********************************************************************************************





More information about the Snort-users mailing list