LinuxLinks.com
Newbies What Next ? News Forums Calendar
News Sections
Home
General News (3770/0)
Reviews (576/0)
Press Releases (450/0)
Distributions (132/0)
Software (515/0)
Hardware (383/0)
Security (188/0)
Tutorials (290/0)
Off Topic (168/0)

Related sites

User Functions
Username:

Password:

Don't have an account yet? Sign up as a New User

Events
There are no upcoming events



Bro

Bro

Bro is a Network Intrusion Detection System (NIDS) that passively monitors network traffic and looks for suspicious activity. 

Bro detects intrusions by first parsing network traffic to extract is application-level semantics and then executing event-oriented analyzers that compare the activity with patterns deemed troublesome. 

Its analysis includes detection of specific attacks (including those defined by signatures, but also those defined in terms of events) and unusual activities (e.g., certain hosts connecting to certain services, or patterns of failed connection attempts). 

 Bro

License
Bro License Agreement

Developer
Vern Paxson

Website
bro-ids.org

Requirements
libpcap
flex
bison or byacc

Support:
Manuals, FAQ
, WikiMailing List

Selected Reviews:

Features include:

  • Network Based
    • Collects, filters, and analyzes traffic that passes through a specific network location
  • Custom Scripting Language
    • Policy scripts are programs written in the Bro language. They contain the "rules" that describe what sorts of activities are deemed troublesome. They analyze the network activity and initiate actions based on the analysis
  • Pre-written Policy Scripts
    • Comes with a rich set of policy scripts designed to detect the most common Internet attacks while limiting the number of false positives, i.e., alerts that confuse uninteresting activity with the important attack activity
    • The supplied policy scripts will run "out of the box" and do not require knowledge of the Bro language or policy script mechanics
  • Powerful Signature Matching Facility
    • Bro policies incorporate a signature matching facility that looks for specific traffic content. 
    • Comes with a set of high value signatures policies, selected for their high detection and low false positive characteristics
  • Network Traffic Analysis
    • Can also analyze network protocols, connections, transactions, data amounts, and many other network characteristics
    • Powerful facilities for storing information about past activity and incorporating it into analyses of new activity
  • Detection Followed by Action
    • Bro policy scripts can generate output files recording the activity seen on the network (including normal, non-attack activity). 
    • Generate problem alerts to event logs, including the operating system syslog facility
    • Scripts can execute programs, which can, in turn, send e-mail messages, page the on-call staff, automatically terminate existing connections, or, with appropriate additional software, insert access control blocks into a router's access control list
  • Snort Compatibility Support
    • Includes a tool, snort2bro, which converts Snort signatures into Bro signatures. 
    • snort2bro also incorporates a large number of enhancements to the standard set of Snort signatures to take advantage of Bro's additional contextual power and reduce false positives

Return to Security Home Page


Last Updated Monday, May 05 2008 @ 08:17 AM EDT


Who's Online
Guest Users: 19

Local Content
Migrating from Windows to Linux
Fedora 7 review
TV Guides
Cedega 4.2.1 Review
Linux Guide
Xandros Desktop OS Version 3.0 Review
Zaurus Software Reviews

Older Stories
Tuesday 05/13
  • DSA-1575-1 linux-2.6 -- denial of service (0)
  • Nexuiz shoots to the top of gaming list (0)

  • Monday 05/12
  • How I dumped Windows for Linux - Day 1 (0)
  • Fedora 9 leaked (0)
  • Microsoft opens arms to Linux (0)
  • Shuttle KPC K-4500 Review (0)

  • Sunday 05/11
  • Linux Equivalents to Windows Software (0)
  • Why we love Ubuntu Linux (or maybe we don't) (0)
  • Intel multi-core threading library supports Sun Studio (0)
  • ARM-based controller has StackableUSB expansion (0)

  • Whats New
    STORIES
    5 stories in last 24 hours

    COMMENTS last 48 hrs
    No new comments

    LINKS last 2 wks
    No recent new links

    Vote

    What do you find MOST attractive about Open Source software?

    Amount of customization
    Security
    Freedom provided
    Speed of development
    Quality
    Multiple versions
    Cost
    Potential to contribute
    Ability to modify code
    Results
    675 votes | 0 comments

    Built with GeekLog and phpBB
    Comments to the webmaster are welcome
    Copyright © 2002 LinuxLinks.com - All rights reserved