Long-time blog readers should know that I don’t rely on tools to defend my enterprise. I rely on people first, followed by tools, then processes. However, today I took a moment to consider the myriad of really cool work happening (mainly) in the open source tool community. When I started counting, I found about seven projects that are likely to help you defend your enterprise.Most of these require some commitment of brainpower and willingness to learn, but I am nevertheless very pleased to see this much innovation on the defensive side. Collectively these projects do not “solve” any problems (nor should they), but I am certain they can help address one or more problems you may encounter — especially regarding visibility. In other words, these are the sorts of tools (with one or two exceptions) that will help you detect and respond to intruders. These are numbered for reference and not for priority.
- Charles Smutz recently announced his Ruminate IDS, whose goal is to “demonstrate the feasibility and value of flexible and scalable analysis of objects transferred through the network.” Charles is also author of the Vortex prohect, a “a near real time IDS and network surveillance engine for TCP stream data.”
- Doug Burks just released a new version of SecurityOnion, an Ubuntu-based live CD to facilitate network security monitoring. You’ll find many of the tools on this list in SO and I expect those missing will be included at some point!
- Over at Berkeley, development of the Bro IDS project is kicking into high gear with Seth Hall’s new role as a full-time developer. We miss you Seth!
- OISF just released a new version of their Suricata IDS. If you’re going to RSA next month, see the OISF team at their next Brainstorming Session. I plan to stop by.
- Dustin Webber and new team member Jason Meller just released a new version of Snorby, a Web 2.0 interface for Snort alerts. I hope to see Snorby packaged in SO soon.
- Edward Bjarte Fjellskål continues to release cool new code, from the packet capture system OpenFPC with Leon Ward to Polman for managing IDS rules.
- Sourcefire’s Razorback framework seems to be making some progress again, and the relaunch of new Snort, VRT, and ClamAV blogs under new community manager Joel Esler is a welcome move.
Check these out if you have some time!