Snare (software)

Snare (software)

Snare (sometimes also written as SNARE, an acronym for System iNtrusion Analysis and Reporting Environment) is a group of open-source agents, and a commercial server, used to collect audit log data from a variety of operating systems and applications to facilitate centralised log analysis. Agents are available for Linux, Windows, Solaris, IIS, Lotus Notes, Irix, AIX, ISA and more.Snare is currently used by hundreds of thousands of individuals and organisations worldwide. [citeweb|title=InterSect Alliance|url=http://www.intersectalliance.com/projects/Snare/|accessdate=2008-06-23]

History

The Snare series of agents began life in 2001 when the team at InterSect Alliance created a Linux kernel module to implement Trusted Computer System Evaluation Criteria auditing at the C2 level.

Agents for Windows, and Solaris soon followed, and additional operating systems, and applications were added to the mix over time.

The Snare Server software was originally designed to meet the needs of Australian-based intelligence agency clients, and distribution was restricted to Australia only. The need for a server solution to compliment the increasingly popular Snare agents, pushed the InterSect Alliance team to find overseas partners, and allow distribution internationally.

Distribution

Snare has been described as the 'De Facto standard for Windows event retrieval' [citeweb|title=Sensage|url=http://www.sensage.com/English/Collaterals/Documents/SenSage_SolutionSheet_AgentlessWindows.pdf|accessdate=2008-06-24] , and because of it's deep roots in the open source movement, coupled with available commercial support options, is used by small non-profit organisations, right up to huge multinational, fortune-500 companies.

Organisations that produce audit server software that competes with the Snare Server software, such as Cisco [citeweb|title=Cisco|url=http://www.cisco.com/en/US/products/ps6241/products_user_guide_chapter09186a008074f1d6.html|accessdate=2008-06-24] , Sensage [citeweb|title=Sensage|url=http://www.sensage.com/English/Collaterals/Documents/SenSage_SolutionSheet_AgentlessWindows.pdf|accessdate=2008-06-24] , and LogLogic [citeweb|title=LogLogic|url=http://www.loglogic.com/log-ed/log-ed-engineer/|accessdate=2008-06-24] , all use and recommend the snare agents to their customers.

Design

The Snare agents have been designed to collect audit log data from a host system, and push the data as quickly as possible, to a central server (or servers), for archive, analysis, and reporting.

The central server can be either a syslog server, a Snare Server appliance, or a custom application. Snare agents are also able to push logs over a data diode in order to facilitate log transfer from networks of low classification to networks of higher classification.

The Snare Server is an appliance, or software-only solution, that provides a variety of analysis tools and to facilitate the collection, analysis, reporting, and archival of audit log data.

References

External links

* [http://www.intersectalliance.com/snareserver/ Commercial server product home page]
* [http://www.intersectalliance.com/projects/ Open-source agents home page]
* [http://sourceforge.net/projects/snare/ SNARE] on SourceForge


Wikimedia Foundation. 2010.

Игры ⚽ Поможем написать курсовую

Look at other dictionaries:

  • Snare — A snare is a kind of trap used for capturing animals. It may also mean:* Snare drum * SNARE (protein), a family of proteins involved in vesicle fusion * The Snares, a group of islands approximately 200 kilometres south of New Zealand * Snare, a… …   Wikipedia

  • Snare — bezeichnet: eine kleine Trommel eine Proteinfamilie, siehe SNARE (Protein) eine Software zur Netzwerküberwachung Snare ist der Familienname folgender Personen: Esbern Snare (1127–1204), dänischer Adeliger und Heerführer …   Deutsch Wikipedia

  • Tiger (security software) — Tiger Security Tool Stable release 3.2.3 / March 3, 2010; 19 months ago (2010 03 03) Operating system Unix, Linux, Solaris Available in English …   Wikipedia

  • Noise gate — A Noise Gate or gate is an electronic device or software that is used to control the volume of an audio signal. In its most simple form, a noise gate allows a signal to pass through only when it is above a set threshold: the gate is open . If the …   Wikipedia

  • Animusic — is an American company specializing in the 3D visualization of MIDI based music. Founded by Wayne Lytle, it is incorporated in New York and has offices in Texas and California. The initial name of the company was Visual Music, changed to Animusic …   Wikipedia

  • Commercial open source applications — Open source software is widely used for private and non commercial applications. In addition, many independent software vendors (ISVs), value added resellers (VARs), and hardware vendors (OEMs or ODMs) use open source frameworks, modules, and… …   Wikipedia

  • Kurzweil K250 — The Kurzweil K250 a.k.a. Kurzweil 250 , K250 or K 250 , manufactured by Kurzweil Music Systems was the first combined live performance and studio electronic musical instrument which produced sound derived from sampled sounds (see:Sampler (musical …   Wikipedia

  • Список коммерческих приложений с открытым исходным кодом — В данном списке представлены наиболее известные примеры коммерческого прикладного программного обеспечения, в большей части или целиком построенного на базе компонентов с открытым исходным кодом. Содержание 1 Бизнес модели коммерческих приложений …   Википедия

  • Dynamic range compression — This article is about a process that intentionally reduces the dynamic range of audio signals. For similar reductions caused by circuit imperfections, see Gain compression. For processes that reduce the size of digital audio files, see Audio… …   Wikipedia

  • Drum machine — For the Windows drumming program, see Drum Machine (software). For the early drum machine computers that used a rotating cylinder as their main memory, see drum memory A Yamaha RY30 Drum Machine A drum machine is an electronic musical instrument… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”