Martin Roesch Snort
Martin Roesch, Snort.org
Snort
Snort is probably the largest and most popular Open Source network intrusion detection system available today. It allows users to monitor their networks for signs of hostile activity, as well as performing a host of other tasks such as mundane as generic packet sniffing or as complex as forensic analysis of network attack traffic.
This talk will discuss the background of Snort, as well as the capabilities and uses of the program. The current architecture of the underlying subsystems that constitute its core functionality will also be examined, in addition to the proposed changes to the system that will be the basis of Snort 2.0. Additionally, the talk will get into the details of what it takes to build a network intrusion detection system and how Snort came to be built.
Martin Roesch is the founder of Sourcefire Inc and has served as President and CEO since its inception. Martin is also the author and lead developer of the open source (GPL) Snort Network Intrusion Detection System (www.snort.org) that forms the foundation of the Sourcefire product line. Over the past five years, he has developed a variety of network security tools and technologies including intrusion detection systems, honeypots, network scanners, and policy enforcement systems for organizations such as GTE Internetworking, Stanford Telecommunications, Inc, and the Department of Defense. He has applied his knowledge of network security to penetration testing and network forensics for a variety of government and large corporate customers over this period as well. Martin holds a B.S. in Electrical and Computer Engineering from Clarkson University.
Black Hat - USA - 2001 Hacking conference
#hacking, #hackers, #infosec, #opsec, #IT, #snort