정보보안기사 실기 대비를 위해 윈도우즈에 snort 를 설치해 실습해보려고 하였으나 뜻대로 되지 않았다.
1. 스노트 홈페이지로 이동
Snort - Network Intrusion Detection & Prevention System
With over 5 million downloads and over 600,000 registered users, it is the most widely deployed intrusion prevention system in the world.
2. 다운로드 받은 파일 설치
텍스트 내용을 보면 Npcap 이 필요하다고 한다.
Snort has successfully been installed.
Snort also requires Npcap 0.9984 to be installed on this machine.
Npcap can be downloaded from:
It would also be wise to tighten the security on the Snort installation
directory to prevent any malicious modification of the Snort executable.
Next, you must manually edit the 'snort.conf' file to
specify proper paths to allow Snort to find the rules files
and classification files.
3. Npcap 설치
4. snort 실행
Running in packet dump mode
--== Initializing Snort ==--
Initializing Output Plugins!
pcap DAQ configured to passive.
The DAQ version does not support reload.
Acquiring network traffic from "\Device\NPF_Loopback".
ERROR: Can't start DAQ (-1) - Error opening adapter: 지정된 경로를 찾을 수 없습니다. (3)!
Fatal Error, Quitting..
Could not create the registry key.
나중에 여유 생기면 오류 해결 도전해보자
