一、linux安装snort:(测试系统是Red Hat Enterprise Linux 5 )
下载snort-2.8.4.1.tar.gz源码包,snort官网:http://www.snort.org/,本文snort版本官网可能没有了,百度找一下吧
获得源码之后,使用tar xvf snort-2.8.4.1.tar.gz -C /root 解压到/root目录下,然后进入源码包目录执行如下命令:
./configure
make
make isntall
mkdir -p /etc/snort/rules
cp /root/源码目录/etc/*.conf /etc/snort/ -fr
cp /root/源码目录/etc/*.confifg /etc/snort/ -fr
cp /root/源码目录/etc/unicode.map /etc/snort/ -fr
mkdir /var/log/snort
如果安装过程提示缺少安装包,使用yum install 包名 进行安装即可。
二、配置snort
百度下载snortrules压缩包,解压到/etc/snort/rules
修改/etc/snort/snort.conf配置文件:var RULE_PATH ../rules -> var RULE_PATH /etc/snort/rules
编辑/etc/snort/rules/icmp.rules,添加alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:"TEST :ICMP PING"; itype:8; sid:20000; rev:3;)
三、启动snort
snort -i eth0 -c /etc/snort/snort.conf -A fast -l /var/log/snort/
四、测试snort入侵检测ping命令
<
.........................................................