Snort & OpenAppID: How to Build an Open Source Next Generation Firewall

DerbyCon 4.0 - Family Rootz

Presented by: Adam Hogan
Date: Friday September 26, 2014
Time: 14:00 - 14:50
Location: Track 4

The Snort team has recently released OpenAppID – the open source implementation of application identification and control. Using this free software you can now implement these next gen features for free! This will provide detailed statistics about what applications are being used in your environment. And with the Snort rules language adapting to this data you can easily write rules to block specific applications (or significantly reduce false positives in other rules). I will show you how to do this, as well as how to write your own application detectors.

Adam Hogan


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats