Thresh (software)
From Wikipedia, the free encyclopedia
Thresh | |
|
|
Developer: | Matthew J. Deren Jr. |
---|---|
Latest release: | 1.5.0b / March 21, 2007 |
OS: | Cross-platform |
Use: | Security / IDS |
License: | GNU General Public License |
Website: | www.automatadigital.com |
Thresh is a free application to assist Security Engineers in tuning Snort IDS sensors. Thresh was written by Matthew Deren, co-creator of Automata Digital. It was designed in Perl-CGI and interfaces with MySQL databases.
This application is capable of generating threshold configurations for Snort Rules via web interface. Thresh reads any MySQL based Snort database and summarizes the events found by alert frequency. Once top-talkers are determined, the administrator can choose to fully suppress the rule from source or destination IP address, or simply reduce the frequency of alerting.
Additionally, there are options to delete alerts from the Snort database directly. Based off the created threshold files, the administrator can view how they will impact the database before changes are applied.
Other applications that can tune alerts in a similar fashion are SnortCenter and SnortCenter2 but these appear to have dropped out of development.
Contents |
[edit] Future development
Future development will include automatic configuration and installation, push-to-sensor capability, pull-from-sensor capability, in-rule tuning and any configuration options which fall under the category of tuning.
[edit] Project homepage
- Thresh - A web-based sensor tuning application
[edit] External links
[edit] Copyright
This work is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License Version 2 as published by the Free Software Foundation.
This work is distributed in the hope that it will be useful, but without any warranty; without even the implied warranty of merchantability or fitness for a particular purpose. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program; if not, write to: Free Software Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA