Snort 3 rule recommendations
Snort 3 rule recommendations are a security tuning feature that
-
automatically tune your intrusion policy with rules specific to the host environment,
-
enable additional rules or tune the current rule set by disabling rules for vulnerabilities not present in your network, and
-
use the host database to determine rules that apply to your environment.
How rule recommendations work
The management center builds a database of hosts on your network with details such as the IP address, hostname, operating system, services, users, and client applications through passive discovery. Based on this information, the system maps vulnerabilities to each discovered host. The recommendations feature uses this host database to determine the rules that apply to your environment.
In Snort 3, there are four security levels, each corresponding to a specific Talos policy:
-
Level 1–Connectivity Over Security
-
Level 2–Balanced Security and Connectivity
-
Level 3–Security Over Connectivity
-
Level 4–Maximum Detection
Check the Accept Recommendations to Disable Rules check box to disable rules for vulnerabilities not found on the hosts in your network. Check this option only if you have to trim your rule set because of a high number of alerts, or to improve inspection performance.
For more information, see Secure Firewall recommended rules.