<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; intrusion-prevention-system</title>
	<atom:link href="http://www.darknet.org.uk/tag/intrusion-prevention-system/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Smooth-Sec &#8211; All In One Pre-Configured IDS/IPS System</title>
		<link>http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/</link>
		<comments>http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/#comments</comments>
		<pubDate>Tue, 22 Mar 2011 08:40:48 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion detection system]]></category>
		<category><![CDATA[intrusion-prevention-system]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[open source ids]]></category>
		<category><![CDATA[open source ips]]></category>
		<category><![CDATA[pre-configured ids]]></category>
		<category><![CDATA[turkey ids]]></category>
		<category><![CDATA[turnkey ids/ips]]></category>
		<category><![CDATA[turnkey ips]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3073</guid>
		<description><![CDATA[Smooth-Sec is a ready to-go IDS/IPS (Intrusion Detection/Prevention System) Linux distribution based on the multi threaded Suricata IDS/IPS engine and Snorby, the top notch web application for network security monitoring. Smooth-Sec is built on Ubuntu 10.04 LTS using the TurnKey Core base as development platform. Functionality is the key point that allows a user to [...]]]></description>
			<content:encoded><![CDATA[<p>Smooth-Sec is a ready to-go  IDS/IPS (Intrusion Detection/Prevention System) Linux distribution based on the multi threaded Suricata IDS/IPS engine and Snorby, the top notch web application for network security monitoring. Smooth-Sec is built on Ubuntu 10.04 LTS using the TurnKey Core base as development platform.</p>
<p>Functionality is the key point that allows a user to deploy a complete IDS/IPS System up and running out of the box within a few minutes, even for security beginners with minimal Linux experience.</p>
<p><strong>Features</strong></p>
<p><em><strong>Snorby</strong></em></p>
<ul>
<li>Metrics Metrics &#038; Reports</li>
<li>Classifications</li>
<li>Full packet and session data.</li>
<li>Settings Custom Settings</li>
<li>Hotkeys</li>
</ul>
<p><em><strong>Suricata</strong></em></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Native IPv6 Support</li>
<li>Automatic protocol detection</li>
<li>Multi threaded</li>
<li>Native hardware acceleration support</li>
<li>Passive OS and Portscan detection</li>
<li>L7 Protocol awareness</li>
<li>IP Reputation using scoring threshold</li>
<li>Distributed blocking &#038; feedback</li>
<li>Global flowbits and variables</li>
</ul>
<p><strong>Details</strong></p>
<p><strong>Snorby login:</strong></p>
<p><strong>Snorby interface:</strong> https://ipaddress<br />
<strong>Username:</strong> snorby@snorby.org<br />
<strong>Password:</strong> snorby  (please change this password after the firts login)</p>
<p><strong>Ssh login:</strong></p>
<p><strong>Username:</strong> root<br />
<strong>Password:</strong> the password you have chose during the installation</p>
<p>You can download Smooth-Sec here:</p>
<p><a href="http://sourceforge.net/projects/smoothsec/files/SmoothSec-1.1.iso/download">SmoothSec-1.1.iso</a></p>
<p>Or read more <a href="http://bailey.st/blog/smooth-sec/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3073+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;t=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;title=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;title=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;title=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;title=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F03%2Fsmooth-sec-all-in-one-pre-configured-idsips-system%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Suricata &#8211; Open Source Next Generation Intrusion Detection and Prevention Engine</title>
		<link>http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/</link>
		<comments>http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/#comments</comments>
		<pubDate>Thu, 13 May 2010 09:22:36 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion detection engine]]></category>
		<category><![CDATA[intrusion detection system]]></category>
		<category><![CDATA[intrusion prevention engine]]></category>
		<category><![CDATA[intrusion-detection]]></category>
		<category><![CDATA[intrusion-prevention]]></category>
		<category><![CDATA[intrusion-prevention-system]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[open source intrusion detection]]></category>
		<category><![CDATA[open source intrusion prevention]]></category>
		<category><![CDATA[open-source]]></category>
		<category><![CDATA[Open-Source-Software]]></category>
		<category><![CDATA[suricata]]></category>
		<category><![CDATA[suricata engine]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2689</guid>
		<description><![CDATA[The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. Basically it&#8217;s a is a multi-threaded intrusion detection/prevention engine engine available from the Open Information [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field.</p>
<p>Basically it&#8217;s a is a multi-threaded intrusion detection/prevention engine engine available from the Open Information Security Foundation </p>
<p>OISF is part of and funded by the Department of Homeland Security&#8217;s Directorate for Science and Technology HOST program (Homeland Open Security Technology), by the the Navy&#8217;s Space and Naval Warfare Systems Command (SPAWAR), as well as through the very generous support of the members of the OISF Consortium. More information about the Consortium is available, as well as a list of our current Consortium Members. </p>
<p>The Suricata Engine and the HTP Library are available to use under the GPLv2. </p>
<p>The HTP Library is an HTTP normalizer and parser written by Ivan Ristic of Mod Security fame for the OISF. This integrates and provides very advanced processing of HTTP streams for Suricata. The HTP library is required by the engine, but may also be used independently in a range of applications and tools. </p>
<p>You can download Suricata v0.9 here:</p>
<p><a href="http://www.openinfosecfoundation.org/download/suricata-0.9.0.tar.gz">suricata-0.9.0.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://www.openinfosecfoundation.org/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2689+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;t=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;title=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;title=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;title=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;title=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F05%2Fsuricata-open-source-next-generation-intrusion-detection-and-prevention-engine%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Impressive Open Source Intrusion Prevention &#8211; HLBR</title>
		<link>http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/</link>
		<comments>http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/#comments</comments>
		<pubDate>Thu, 14 Sep 2006 05:35:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion-prevention]]></category>
		<category><![CDATA[intrusion-prevention-system]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[open-source]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/</guid>
		<description><![CDATA[It&#8217;s good to see work on open source tools in the countermeasure department aswell as the attack and penetration arena. It&#8217;s a shame since Snort and Nessus have gone semi-commercial. I hope more people invest their time in good IDS, Firewall and IPS systems, I love things like IPCop and hope to see more products [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It&#8217;s good to see work on open source tools in the countermeasure department aswell as the attack and penetration arena.</p>
<p>It&#8217;s a shame since Snort and Nessus have gone semi-commercial.</p>
<p>I hope more people invest their time in good IDS, Firewall and IPS systems, I love things like IPCop and hope to see more products like HLBR.</p>
<p>HLBR is a brazilian project, started in november 2005, as a fork of the Hogwash project (started by Jason Larsen in 1996)</p>
<p>HLBR is an IPS (Intrusion Prevention System) that can filter packets directly in the layer 2 of the OSI model (so the machine doesn&#8217;t need even an IP address). Detection of malicious/anomalous traffic is done by rules based in signatures, and the user can add more rules. It is an efficient and versatile IPS, and it can even be used as bridge to honeypots and honeynets. Since it doesn&#8217;t make use of the operating system&#8217;s TCP/IP stack, it can be &#8220;invisible&#8221; to network access and attackers.</p>
<p>Since version 1.0, released in march 5th 2006, HLBR can use regular expressions to detect intrusion attempts, virus, worms, and phishing.</p>
<p>You can view the entire <a href="http://svn.sourceforge.net/viewvc/hlbr/tags/HLBR_1_1/hlbr/README.en?view=markup">HLBR README file here</a>.</p>
<p></p>
<p>Go to the <a href="http://hlbr.sourceforge.net/index-en.html">HLBR Homepage</a> for more information and downloads.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D126+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;t=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;title=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;title=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;title=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;title=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F09%2Fimpressive-open-source-intrusion-prevention-hlbr%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

