Author Archives: Mike Lococo

Capacity Planning for Snort IDS

Snort is a very capable network intrusion detection system, but planning a first-time hardware purchase can be difficult. It requires fairly deep knowledge of x86 server performance, network usage patterns at your site, along with some snort-specific knowledge. Documentation is … Continue reading

Posted in geekery | 6 Comments

Monitoring Snort Performance with Zabbix

In January I gave a presentation to the REN-ISAC on how to monitor the performance of Snort IDS systems. It covers: A comparison of high-performance capture-frameworks like vanilla-libpcap vs pfring vs dedicated capture cards from Endace or similar. An overview … Continue reading

Posted in geekery | 2 Comments

Relaunch

My RSS subscriber has reminded me that my feeds have gone a little bit wild over the last couple of days as I’ve gone through old posts to retag and update dead links. That’s all finished now, promise. I’ve been … Continue reading

Posted in geekery | Tagged , , | 1 Comment

Virtualization and Security Boundaries

Virtualization security is coming up frequently in higher-ed security forums as folks scramble to understand best-practices before whatever path-of-least-resistance gets too entrenched to change.  Unfortunately, there’s almost no intermediate-level documents on virtualization security to help us wrap our heads around … Continue reading

Posted in geekery, personal | Tagged , | Leave a comment

Fedora 8 on a Dell Latitude D620

Fedora 8 works quite well on the D620 right out of the box, and with a few tweaks can be just about fully supported. This guide summarizes what I’ve done to get things working to my satisfaction. It is not … Continue reading

Posted in geekery | Tagged , , , , , | Leave a comment