[Snort-users] NIDS on large (>500MB) pcap dumps
smarotta at ...16014...
Fri Dec 14 17:41:36 EST 2012
Okay, so I found an old copy of Snort and got it running. At least, it seems to be. The summary looks correct. Now what I'd really like is a text file containing a list of events as they occur in my pcap dump. I've got a log file but it appears to be binary. As for what constitutes an event, I suppose an intrusion attempt, a normal transaction, any sort of high-level event that's more than just a list of individual packets would be nice.
THIS MESSAGE IS INTENDED FOR THE USE OF THE PERSON TO WHOM IT IS ADDRESSED. IT MAY CONTAIN INFORMATION THAT IS PRIVILEGED, CONFIDENTIAL AND EXEMPT FROM DISCLOSURE UNDER APPLICABLE LAW. If you are not the intended recipient, your use of this message for any purpose is strictly prohibited. If you have received this communication in error, please delete the message and notify the sender so that we may correct our records.
From: Steve Marotta
Sent: Friday, December 14, 2012 5:07 PM
To: 'Balasubramaniam Natarajan'
Cc: snort-users at lists.sourceforge.net
Subject: RE: [Snort-users] NIDS on large (>500MB) pcap dumps
Thanks to everyone for the responses. I compiled Snort from source (I had originally installed using Ubuntu apt-get), configuring it with --enable-large-pcap. I downloaded rule set 2930 and set it up, configured the snort.conf file, and when I try to run it now, I get:
ERROR: The dynamic detection library "/usr/local/snort/lib/snort_dynamicrules/imap.so" version 1.0 compiled with dynamic engine library version 1.16 isn't compatible with the current dynamic engine library "/usr/local/snort/lib/snort_dynamicengine/libsf_engine.so" version 1.17.
Fatal Error, Quitting..
Both of these files are in the same rule set that I downloaded. I can understand a conflict between two different things that I've installed, but a conflict between two items in one package is puzzling.
So I'm figuring that the issue is that I installed Snort version 2.9.4 but could only get rulesets for 2.9.3.x. I'm looking around for an older version of Snort so I can use the only rules I can get access to, and I can't seem to find anywhere that lets me download 220.127.116.11 or 18.104.22.168. Am I missing something?
More information about the Snort-users