1. Configure preprocessors  ÇÁ·ÎÇÁ·Î¼¼¼ ¼³Á¤Àº »ç¿ëÀÚ°¡ snort ¿¡ Áö¿øµÇ´Â ¿©·¯°¡Áö plugin ¸¦ ½±°Ô »ç¿ëÇÒ¼ö ÀÖµµ·Ï ÇÑ´Ù.  ¼³Á¤ Çü½ÄÀº ´ÙÀ½°ú °°´Ù. 
  ----------------------------------------------------------  preprocessor <name_of_processor>: <configuration_options>  ---------------------------------------------------------- 
  preprocessor ·Î´Â ´ÙÀ½°ú °°´Ù. 
  Minfrag  -------  minfrag ´Â ¾ÆÁÖ ÀÛ°Ô Á¶°¢³ ÆÐŶÀ» ŽÁöÇÏ´Â ¿ªÈ°À» ÇÑ´Ù.  °ø°ÝÀڴ ħÀÔŽÁö ÅøÀ» ÇÇÇϱâ À§Çؼ ÆÐŶÀ» Àß°Ô Àß°Ô ÂɰԼ º¸³»±âµµ Çϴµ¥ ÀÌ·¸°Ô µÇ¸é Á¶°¢³ ÆÐŶ¿¡ ´ëÇØ ÆÐÅϰ˻縦 Çϱ⠶§¹®¿¡ Á¤È®ÇÑ °Ë»ç¸¦ ÇÒ¼ö ¾ø´Ù. ±×·¯¹Ç·Î ¸î ¹ÙÀÌÆ® ¹Ì¸¸ÀÇ ÆÐŶÀÌ µé¾î¿À¸é °æ°í¸¦ ÇØÁÖ°Ô µÈ´Ù. 
  »ç¿ë¹æ¹ý : preprocessor minfrag:128 //128byte ÀÌÇÏÀÇ ÆÐŶÀº °æ°í. 
  Defrag  ------  defrag preprocessor ´Â Á¶°¢µÈ ÆÐŶÀ» °æ°íÇÏ´Â minfrag ¿Í´Â ´Þ¸® À̸¦ °¨Áö Çϰí IP ÆÐŶÀ» ÀçÁ¶ÇÕ ÇÑ´Ù. minfrag º¸´Ù´Â °·ÂÇÑ Å½Áö¸¦ ÇÒ¼ö ÀÖ´Ù. ÇÏÁö¸¸ À̸¦ »ç¿ëÇÒ °æ¿ì ½Ã½ºÅÛ¿¡ ¸¹Àº ºÎÇϰ¡ °É·Á Àü¼Û·®ÀÌ ¸¹Àº ³×Æ®¿÷¿¡¼´Â ÁÖÀǸ¦ ÇØ¾ß ÇÒ°ÍÀÌ´Ù. 
  »ç¿ë¹æ¹ý : preprocessor defrag // ¿É¼Ç ¾øÀ½ 
  Stream  ------  stream Àº TCP stream À» ÀçÁ¶ÇÕÇÏ¿© ŽÁöÀ²À» ³ôÀδÙ. ÇÏÁö¸¸ À̰Ϳª½Ã ¸¹Àº ½Ã½ºÅÛ ºÎÇϸ¦ ÀÏÀ¸Å°°Ô µÈ´Ù. ÅÚ³ÝÀ̳ª ftp, web Á¤µµÀÇ ¼ºñ½º¸¦ ÇÏ´Â port Á¤µµ¸¦ Á¶ÇÕÇϸé ÁÁÀ»°Å °°´Ù.  ±×¸®°í  stream À» »ç¿ëÇÒ¶§ ÁÖÀÇÇÒÁ¡ÀÌ Çϳª ÀÖ´Ù. ¼³Á¤ À§Ä¡ Àε¥... stream preprocessor ´Â ¹Ýµå½Ã defrag µÚ¿¡ , http_decode º¸´Ù´Â ¾Õ¿¡ ¼³Á¤ÀÌ µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù. 
  »ç¿ë¹æ¹ý : preprocessor stream2: timeout 10, ports 21 23,  maxbytes 16384 
  timeout : ÃÊ´ÜÀ§·Î ÆÐŶÀÌ ¾øÀ»¶§ stream À» ¾ó¸¶°£ °è¼ÓÇÒ°ÍÀÎÁö °áÁ¤  port : Á¶ÇÕÇÒ ÆÐŶÀÌ µé¾î ¿À´Â port  maxbytes ´Â ÆÐŶÀ» ÀçÁ¶ÇÕÇÒ ÃÖ´ë Å©±â¸¦ ¸»ÇÑ´Ù. 
  HTTP Decode  ------------  http_decode ´Â HTTP URL ¹®ÀÚ¿ÀÌ ¾Ë¾Æº¸Áö ¸øÇÏ°Ô µÇÀÖ´Â °æ¿ì ±×°ÍÀ» snort ¿£Áø¿¡¼ ¾Ë¾Æº¼¼ö ÀÖ´Â ¹®ÀÚ¿·Î º¯È¯. 
  »ç¿ë¹æ¹ý : preprocessor http_decode: 80 -unicode -cginull 
  Portscan  ---------  Portscan °ø°ÝÀ» ŽÁöÇÏ°í ·Î±×¸¦ ³²±â°Ô µÈ´Ù. 
  »ç¿ë¹æ¹ý: preprocessor portscan: $HOME_NET 4 3 portscan.log 
  Portscan Ignorehosts  ---------------------  portscan detector °¡ ÀÛµ¿ÇÏÁö ¾Ê¾Æ¾ß ÇÒ IP ¸®½ºÆ®¸¦ ÁöÁ¤ÇÒ¼ö ÀÖ´Ù. 
  »ç¿ë¹æ¹ý: portscan-ignorehosts: <host list> 
 
  2. Config output plugins  ÆÐŶ °¨½Ã °á°ú¸¦ Ãâ·ÂÇÒ¶§ »ç¿ëµÇ´Â plugins À» ÁöÁ¤ÇÏ´Â °ÍÀÌ´Ù.  °¢ plugin ¸¶´Ù..Ãâ·ÂÇÏ´Â °¢°¢ÀÇ Ãâ·ÂÇüŸ¦ °¡Áö°í Àֱ⿡ ¾î¶²½ÄÀ¸·Î Ãâ·ÂÀ» ÇÒ°ÍÀÎÁö¸¦ À̰÷¿¡¼ °áÁ¤ÇÏ¸é µÈ´Ù.  »ç¿ëµÇ´Â plugin module Á¾·ù´Â ´ÙÀ½°ú °°´Ù. 
  Alert_syslog : alert ¸¦ syslog ·Î º¸³» ¹ö¸°´Ù. 
  Alert_fast : alert ·Î±×¸¦ ³²±æ¶§ output file ÀÌ ÇѶóÀÎÀ¸·Î ³²±â±â ¶§¹®¿¡ ¹«Ã´ ºü¸£´Ù. 
  Alert_full : alert ·Î±×¸¦ ³²±æ¶§ output file ¿¡ ¸ðµç ·Î±×¸¦ ³²±â±â ¶§¹®¿¡ »ó´çÈ÷ ´À¸®´Ù. 
  Alert_smb : alert ¸¦ ÁÙ¶§ WinPopup Çü½ÄÀ¸·Î netbios ¸¦ »ç¿ëÇÏ´Â ¿ø°Ý ¸Ó½Å¿¡ °æ°í¸¦ ³¯·Á ÁØ´Ù. 
  Alert_unixsock : Unix domain socketÀ» ¼³Ä¡Çؼ À̰÷À¸·Î alert¸¦ ÁØ´Ù. 
  log_tcpdump : log packets ¸¦ tcpdump ÇüÅ·Π¹Ù²Ù¾î outfile À» ³²±ä´Ù. 
  database : snort ÀÇ data ¸¦ mysql,postgresql µîÀ¸·Î ÀúÀåÇÑ´Ù. 
  Alert_smb : alert ¸¦ ÁÙ¶§ WinPopup Çü½ÄÀ¸·Î netbios ¸¦ »ç¿ëÇÏ´Â ¿ø°Ý¸Ó½Å¿¡ °æ°í¸¦ ³¯·Á ÁØ´Ù. 
  Alert_unixsock : Unix domain socketÀ» ¼³Ä¡Çؼ À̰÷À¸·Î alert¸¦ ÁØ´Ù. 
  log_tcpdump : log packets ¸¦ tcpdump ÇüÅ·Π¹Ù²Ù¾î outfile À» ³²±ä´Ù. 
  database : snort ÀÇ data ¸¦ mysql,postgresql µîÀ¸·Î ÀúÀåÇÑ´Ù. 
 
  3. Rule set config  Snort Rule set ¼³Á¤ÆÄÀÏÀ» snort.conf ÆÄÀÏ¿¡¼ include ¸¦ ÀÌ¿ëÇØ¼ °¡Á® ¿Â´Ù.  include xxxxxxx.rules 
  ÁÖÀÇ ÇÒÁ¡Àº c ¾ð¾î¿Í °°ÀÌ include ¹® ¸¶Áö¸·¿¡ ; ¸¦ »ç¿ëÇÏÁö ¾Ê´Â´Ù.  
        
         
        
        
        
        
        
        
        
         
     |