Network-Intrusion-Detection-System (NIDS), das den Netzwerkverkehr überwacht und versucht, verdächtige Aktivitäten, Pakete und Verbindungen zu erkennen; wird eine solche erkannt, bietet das Programm dem Benutzer weitere Optionen wie Blockieren, Umgehen oder Reinigen an.
Lizenz: Open Source
Whats new: >>Suricata 2.0 Beta 1:
New features:
· Luajit flow vars and flow ints support
· DNS parser, logger and keyword support
· deflate support for HTTP response bodies
Improvements:
· update to libhtp 0.5
· improved gzip support for HTTP response bodies
· redesigned transaction handling, improving both accuracy and performance
· redesigned CUDA support
· Be sure to always apply verdict to NFQ packet
· stream engine: SACK allocs should adhere to memcap
· stream: deal with multiple different SYN/ACK’s better
· stream: Randomize stream chunk size for raw stream inspection
· Introduce per stream thread ssn pool
· pass” IP-only rules should bypass detection engine after matching
· Generate error if bpf is used in IPS mode
· Add support for batch verdicts in NFQ
· Update Doxygen config
· Improve libnss detection
Fixes:
· Fix a FP on rules looking for port 0 and fragments
· OS X unix socket build fixed
· bytetest, bytejump and byteextract negative offset failure
· Fix fast.log formatting issues
· Invalidate negative depth
· Fixed accuracy issues with relative pcre matching
· Fix deadlock in flowvar capture code
· Improved accuracy of file_data keyword
· Fix af-packet ips mode rule processing bug
· stream: fix injecting pseudo packet too soon leading to FP
Suricata 1.4.5:
· ipv6 extension header parsing issue causing Suricata to hang
· icmp_seq and icmp_id keyword with icmpv6 traffic FP & FN
http://suricata-ids.org/