Snare (software)

Snare (sometimes also written as SNARE, an acronym for System iNtrusion Analysis and Reporting Environment) is a group of open-source agents, and a commercial server, used to collect audit log data from a variety of operating systems and applications to facilitate centralised log analysis. Agents are available for Linux, Windows, Solaris, IIS, Lotus Notes, Irix, AIX, ISA and more. Snare is currently used by hundreds of thousands of individuals and organisations worldwide.[1]

Contents

History

The Snare series of agents began life in 2001 when the team at InterSect Alliance created a Linux kernel module to implement Trusted Computer System Evaluation Criteria auditing at the C2 level.

Agents for Windows, and Solaris soon followed, and additional operating systems, and applications were added to the mix over time.

The Snare Server software was originally designed to meet the needs of Australian-based intelligence agency clients, and distribution was restricted to Australia only. The need for a server solution to complement the increasingly popular Snare agents, pushed the InterSect Alliance team to find overseas partners, and allow distribution internationally.

Distribution

Snare has been described as the 'De Facto standard for Windows event retrieval' [2], and because of its deep roots in the open source movement, coupled with available commercial support options, is used by small non-profit organisations, right up to huge multinational, Fortune-500 companies.

Organisations that produce audit server software that competes with the Snare Server software, such as Cisco [3], Sensage [4], and LogLogic [5], all use and recommend the Snare agents to their customers.

Design

The Snare agents have been designed to collect audit log data from a host system, and push the data as quickly as possible, to a central server (or servers), for archive, analysis, and reporting.

The central server can be either a syslog server, a Snare Server appliance, or a custom application. Snare agents are also able to push logs over a unidirectional network in order to facilitate log transfer from networks of low classification to networks of higher classification.

The Snare Server is an appliance, or software-only solution, that provides a variety of analysis tools and to facilitate the collection, analysis, reporting, and archival of audit log data.

References

http://www.intersectsecurity.com/docs/Snare_enterprise_agents_Symtrex.pdf

External links