4 ms·
(Disclaimer: Bro team member) First, Bro is a Turing-complete scripting language ("the Python for the network") and Snort/Suricata a system centered around reg
by mavam 12y ago
(Disclaimer: Bro team member)
First, Bro is a Turing-complete scripting language ("the Python for the network") and Snort/Suricata a system centered around regular-expression matching [1]. These two paradigms have fundamentally different levels of expressiveness.
Second, Bro's core is policy-neutral. That means has no preconceived notion of good or bad, it simply provides information about activity. On top of that, it ships with numerous policy scripts to detect actual attacks. For example, there exists an SSH analyzer simply reporting the banner for each connection and byte-heuristic for detecting successful logins. On top, there exists another script that attempts to detect brute-forces by simply counting connection attempts per unit time. On the contrary, operators feed Snort/Suricata with rules which feed the system with malicious data. Your analysis is only as good as your rule set. As such, the systems spit out mostly attacks, which are useful iff calibrated to not emit a ton of false positivies.
[1] Snort features numerous enhancements for state tracking, but these are one-offs and hard-wired. For example, Snort supports "pre-processers" written C, which integrate at a much lower level of abstraction.