[Snort-users] Rule Selection

Rudi Starcevic tech at ...12014...
Wed Feb 9 16:33:48 EST 2005


Hi,

A colleague of mine suggested to me that a machine with only port 80 
open ( www server ) one should only use www Snort rules.
That would mean not using alot of available rules for intrusion 
detection, is that wise ?

Thanks
Best regards
Rudi






More information about the Snort-users mailing list