In this article, I’m going to resume the steps to have a full packet capture solution with snort IDS and Intel NIC’s.
This solutions is based on Luca Deri’s software PF_RING, a new type of socket to exploit the capabilities of packet capture and snort.
We will follow these steps
- Download and compile PF_RING
- Compile the PF_RING aware network driver
- Compile the libpcap
- Download and compile DAQ
- Compile PF_RING DAQ module
- Download and compile snort agains DAQ