Talk With an Expert

How Can You Build and Leverage SNORT IDS Metrics to Reduce Risk?

How Can You Build and Leverage SNORT IDS Metrics to Reduce Risk? (PDF, 3.45MB)Published: 19 Sep, 2013
Created by
Tim Proffitt

Many organizations have deployed Snort sensors at their ingress points. Some may have deployed them between segmented internal networks. Others may have IDS sensors littered throughout the organization. Regardless of how the sensor is placed the IDS can provide a significant view into traffic crossing the network. With this data already being generated, how many organizations create metrics for further analysis? What metrics are valuable to security teams and how are they used? What insights can one gain by good metrics and how can that be used to reduce risk to the organization? The paper will cover current technologies and techniques that can be used to create valuable metrics to aide security teams into making informed decisions.