<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Emerging-Threats on Inliniac</title>
    <link>https://inliniac.net/blog/tag/emerging-threats/</link>
    <description>Recent content in Emerging-Threats on Inliniac</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 07 Nov 2013 14:37:04 +0000</lastBuildDate>
    <atom:link href="https://inliniac.net/blog/tag/emerging-threats/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Suricata profiling per keyword</title>
      <link>https://inliniac.net/blog/2013/11/07/suricata-profiling-per-keyword/</link>
      <pubDate>Thu, 07 Nov 2013 14:37:04 +0000</pubDate>
      <guid>https://inliniac.net/blog/2013/11/07/suricata-profiling-per-keyword/</guid>
      <description>&lt;p&gt;Last week I&amp;rsquo;ve added some more profiling options to Suricata. It&amp;rsquo;s part of the current git master. It&amp;rsquo;s enabled only when &lt;code&gt;--enable-profiling&lt;/code&gt; and then through the suricata.yaml:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;profiling:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  # per keyword profiling&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  keywords:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    enabled: yes&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    filename: keyword_perf.log&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    append: yes&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This will output a table similar to below:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;&#34;&gt;&lt;code class=&#34;language-gdscript3&#34; data-lang=&#34;gdscript3&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Date: &lt;span style=&#34;color:#ae81ff&#34;&gt;11&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;/&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;7&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;/&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;2013&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;15&lt;/span&gt;:&lt;span style=&#34;color:#ae81ff&#34;&gt;13&lt;/span&gt;:&lt;span style=&#34;color:#ae81ff&#34;&gt;11&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: total&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;threshold        &lt;span style=&#34;color:#ae81ff&#34;&gt;355324491&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;190574&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;409&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;72276&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1864.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;3625.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1860.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;content          &lt;span style=&#34;color:#ae81ff&#34;&gt;1274592063&lt;/span&gt;  &lt;span style=&#34;color:#ae81ff&#34;&gt;534328&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;196738&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;312321&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;2385.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2424.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2362.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;pcre             &lt;span style=&#34;color:#ae81ff&#34;&gt;56626031&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;11149&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;824&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;254562&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;5079.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;12234.00&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;4507.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;byte_test        &lt;span style=&#34;color:#ae81ff&#34;&gt;153287955&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;128254&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;32109&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;67989&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1195.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1658.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1040.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;byte_jump        &lt;span style=&#34;color:#ae81ff&#34;&gt;3676404&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2041&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2041&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;15939&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1801.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1801.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;flow             &lt;span style=&#34;color:#ae81ff&#34;&gt;38276182&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;22842&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;22842&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;63987&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1675.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1675.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;isdataat         &lt;span style=&#34;color:#ae81ff&#34;&gt;580764&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;558&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;556&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;2427&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1040.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1040.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1017.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;dsize            &lt;span style=&#34;color:#ae81ff&#34;&gt;2212029&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2062&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2061&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;3711&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1072.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1072.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;789.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;flowbits         &lt;span style=&#34;color:#ae81ff&#34;&gt;1677209&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;874&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;870&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;9873&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1919.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1923.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;884.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;itype            &lt;span style=&#34;color:#ae81ff&#34;&gt;1653&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1386&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;826.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;267.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;1386.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;icode            &lt;span style=&#34;color:#ae81ff&#34;&gt;27383781&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;93827&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;25545&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;291.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;1021.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;291.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;flags            &lt;span style=&#34;color:#ae81ff&#34;&gt;192751968&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;245519&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;189709&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;255639&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;785.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;753.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;892.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;urilen           &lt;span style=&#34;color:#ae81ff&#34;&gt;6149297&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;6142&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1099&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;28299&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1001.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1395.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;915.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;byte_extract     &lt;span style=&#34;color:#ae81ff&#34;&gt;143091&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;78&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;78&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;7743&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1834.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1834.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: packet&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;flow             &lt;span style=&#34;color:#ae81ff&#34;&gt;38276182&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;22842&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;22842&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;63987&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1675.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1675.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;dsize            &lt;span style=&#34;color:#ae81ff&#34;&gt;2212029&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2062&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2061&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;3711&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1072.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1072.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;789.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;flowbits         &lt;span style=&#34;color:#ae81ff&#34;&gt;351171&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;294&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;290&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;5526&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1194.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1198.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;884.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;itype            &lt;span style=&#34;color:#ae81ff&#34;&gt;1653&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1386&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;826.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;267.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;1386.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;icode            &lt;span style=&#34;color:#ae81ff&#34;&gt;27383781&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;93827&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;25545&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;291.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;1021.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;291.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;flags            &lt;span style=&#34;color:#ae81ff&#34;&gt;192751968&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;245519&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;189709&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;255639&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;785.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;753.00&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;892.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: packet&lt;span style=&#34;color:#f92672&#34;&gt;/&lt;/span&gt;stream payload&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;content          &lt;span style=&#34;color:#ae81ff&#34;&gt;1203990910&lt;/span&gt;  &lt;span style=&#34;color:#ae81ff&#34;&gt;512902&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;183628&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;312321&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;2347.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2365.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2337.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;pcre             &lt;span style=&#34;color:#ae81ff&#34;&gt;28087301&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;6598&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;54&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;254562&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;4256.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;12279.00&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;4190.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;byte_test        &lt;span style=&#34;color:#ae81ff&#34;&gt;153287955&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;128254&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;32109&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;67989&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1195.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1658.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1040.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;byte_jump        &lt;span style=&#34;color:#ae81ff&#34;&gt;3676404&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2041&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2041&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;15939&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1801.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1801.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;isdataat         &lt;span style=&#34;color:#ae81ff&#34;&gt;578172&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;556&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;554&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;2427&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1039.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1039.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1017.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;byte_extract     &lt;span style=&#34;color:#ae81ff&#34;&gt;143091&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;78&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;78&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;7743&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1834.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1834.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: http uri&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;content          &lt;span style=&#34;color:#ae81ff&#34;&gt;44775802&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;13102&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;8351&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;60993&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;3417.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;3257.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;3698.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;pcre             &lt;span style=&#34;color:#ae81ff&#34;&gt;18284421&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;3646&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;97&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;61338&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;5014.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;8916.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;4908.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;isdataat         &lt;span style=&#34;color:#ae81ff&#34;&gt;2592&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1725&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;1296.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1296.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;urilen           &lt;span style=&#34;color:#ae81ff&#34;&gt;6149297&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;6142&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1099&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;28299&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1001.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1395.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;915.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: http raw uri&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;pcre             &lt;span style=&#34;color:#ae81ff&#34;&gt;9534&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;4953&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;4767.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;4767.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: http client body&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;content          &lt;span style=&#34;color:#ae81ff&#34;&gt;1556904&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;441&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;181&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;58476&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;3530.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2874.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;3986.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;pcre             &lt;span style=&#34;color:#ae81ff&#34;&gt;63924&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;6&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;6&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;17358&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;10654.00&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;10654.00&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: http headers&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;content          &lt;span style=&#34;color:#ae81ff&#34;&gt;23688244&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;7631&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;4348&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;31098&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;3104.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;3311.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2829.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;pcre             &lt;span style=&#34;color:#ae81ff&#34;&gt;9998970&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;859&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;667&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;71904&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;11640.00&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;12727.00&lt;/span&gt;    &lt;span style=&#34;color:#ae81ff&#34;&gt;7862.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: http stat code&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;content          &lt;span style=&#34;color:#ae81ff&#34;&gt;80052&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;39&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;20&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;3699&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;2052.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2199.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1898.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: http method&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;content          &lt;span style=&#34;color:#ae81ff&#34;&gt;476334&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;203&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;201&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;27240&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;2346.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2351.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1846.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: http cookie&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;content          &lt;span style=&#34;color:#ae81ff&#34;&gt;23817&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;10&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;9&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;2763&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;2381.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2384.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2358.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;pcre             &lt;span style=&#34;color:#ae81ff&#34;&gt;181881&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;38&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;13095&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;4786.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;4786.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: post&lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt;match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;flowbits         &lt;span style=&#34;color:#ae81ff&#34;&gt;1326038&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;580&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;580&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;9873&lt;/span&gt;        &lt;span style=&#34;color:#ae81ff&#34;&gt;2286.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;2286.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;0.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Stats &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt;: threshold&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;--------------------------------------------------------------------------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keyword          Ticks       Checks   Matches  Max Ticks   Avg         Avg Match   Avg No Match&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;----------------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;--------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-----------&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;threshold        &lt;span style=&#34;color:#ae81ff&#34;&gt;355324491&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;190574&lt;/span&gt;   &lt;span style=&#34;color:#ae81ff&#34;&gt;409&lt;/span&gt;      &lt;span style=&#34;color:#ae81ff&#34;&gt;72276&lt;/span&gt;       &lt;span style=&#34;color:#ae81ff&#34;&gt;1864.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;3625.00&lt;/span&gt;     &lt;span style=&#34;color:#ae81ff&#34;&gt;1860.00&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The first part has the totals for all keywords. After this the stats are broken down per buffer type.&lt;/p&gt;</description>
    </item>
    <item>
      <title>More on Suricata lua flowints</title>
      <link>https://inliniac.net/blog/2013/04/23/more-on-suricata-lua-flowints/</link>
      <pubDate>Tue, 23 Apr 2013 10:17:52 +0000</pubDate>
      <guid>https://inliniac.net/blog/2013/04/23/more-on-suricata-lua-flowints/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/09/lua.gif&#34; alt=&#34;&#34;&gt;This morning I added flowint lua functions for incrementing and decrementing flowints. From the &lt;a href=&#34;https://github.com/inliniac/suricata/commit/9571091e53a2103cbc9926242fa2cb003eb412ec&#34;&gt;commit&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Add flowint lua functions for incrementing and decrementing flowints.&lt;/p&gt;&#xA;&lt;p&gt;First use creates the var and inits to 0. So a call:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    a = ScFlowintIncr(0)&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Results in a == 1.&lt;/p&gt;&#xA;&lt;p&gt;If the var reached UINT_MAX (2^32), it&amp;rsquo;s not further incremented. If the&#xA;var reaches 0 it&amp;rsquo;s not decremented further.&lt;/p&gt;&#xA;&lt;p&gt;Calling ScFlowintDecr on a uninitialized var will init it to 0.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suricata Lua scripting flowint access</title>
      <link>https://inliniac.net/blog/2013/04/22/suricata-lua-scripting-flowint-access/</link>
      <pubDate>Mon, 22 Apr 2013 16:16:30 +0000</pubDate>
      <guid>https://inliniac.net/blog/2013/04/22/suricata-lua-scripting-flowint-access/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/09/lua.gif&#34; alt=&#34;&#34;&gt;A few days ago I wrote about my Emerging Threats sponsored &lt;a href=&#34;https://inliniac.net/blog/2013/04/18/suricata-lua-scripting-flowvar-access/&#34; title=&#34;Suricata Lua scripting flowvar access&#34;&gt;work&lt;/a&gt; to support flowvars from Lua scripts in Suricata.&lt;/p&gt;&#xA;&lt;p&gt;Today, I updated that support. Flowvar &amp;lsquo;sets&amp;rsquo; are now real time. This was needed to fix some issues where a script was invoked multiple times in single rule, which can happen with some buffers, like HTTP headers.&lt;/p&gt;&#xA;&lt;p&gt;Also, I implemented flowint support. Flowints in Suricata are integers stored in the flow context.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suricata Lua scripting flowvar access</title>
      <link>https://inliniac.net/blog/2013/04/18/suricata-lua-scripting-flowvar-access/</link>
      <pubDate>Thu, 18 Apr 2013 16:36:56 +0000</pubDate>
      <guid>https://inliniac.net/blog/2013/04/18/suricata-lua-scripting-flowvar-access/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/09/lua.gif&#34; alt=&#34;&#34;&gt;Funded by Emerging Threats, I&amp;rsquo;ve been working on giving the lua scripts access to flowvars.&lt;/p&gt;&#xA;&lt;p&gt;Currently only &amp;ldquo;flowvars&amp;rdquo; are done, &amp;ldquo;flowints&amp;rdquo; will be next. Please review the code at:&#xA;&lt;a href=&#34;https://github.com/inliniac/suricata/tree/dev-lua-flowvar&#34;&gt;https://github.com/inliniac/suricata/tree/dev-lua-flowvar&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Pcre based flowvar capturing is done in a post-match fashion. If the rule containing the &amp;ldquo;capture&amp;rdquo; matches, the var is stored in the flow.&lt;/p&gt;&#xA;&lt;p&gt;For lua scripting, this wasn&amp;rsquo;t what the rule writers wanted. In this case, the flowvars are stored in the flow regardless of a rule match.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Closing in on Suricata 1.4</title>
      <link>https://inliniac.net/blog/2012/11/29/closing-in-on-suricata-1-4/</link>
      <pubDate>Thu, 29 Nov 2012 16:50:15 +0000</pubDate>
      <guid>https://inliniac.net/blog/2012/11/29/closing-in-on-suricata-1-4/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/07/suricata2.png&#34; alt=&#34;&#34;&gt;I just made &lt;a href=&#34;http://suricata-ids.org/2012/11/29/suricata-1-4rc1-available/&#34;&gt;Suricata 1.4rc1&lt;/a&gt; available with some pretty exciting features: unix socket mode and IP reputation.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Unix socket&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;First of all, &lt;a href=&#34;https://home.regit.org/2012/09/a-new-unix-command-mode-in-suricata/&#34;&gt;Eric Leblond&amp;rsquo;s work&lt;/a&gt; on the Unix socket was merged. The unix socket work consists of two parts. The unix socket protocol implementation and a new runmode.&lt;/p&gt;&#xA;&lt;p&gt;The protocol implementation is based on JSON messages over unix socket. Eric will be fully documenting it soon. Currently the commands are limited to shutting down and getting some basic stats. This part isn&amp;rsquo;t very exciting yet, but the groundwork for many future extensions has been laid.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IP Reputation in Suricata</title>
      <link>https://inliniac.net/blog/2012/11/21/ip-reputation-in-suricata/</link>
      <pubDate>Wed, 21 Nov 2012 19:22:01 +0000</pubDate>
      <guid>https://inliniac.net/blog/2012/11/21/ip-reputation-in-suricata/</guid>
      <description>&lt;p&gt;&lt;em&gt;Disclaimer: this work was sponsored by &lt;a href=&#34;http://www.emergingthreatspro.com/&#34;&gt;Emerging Threats Pro&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;One thing we&amp;rsquo;ve been talking about for many years at OISF is IP Reputation. The basic idea is that many organizations have information about specific IP-addresses. This information may be that a host is infected, acts as a spam relay or many other things. We&amp;rsquo;ve always thought it might be useful to apply this info to the IDS directly.&lt;/p&gt;&#xA;&lt;p&gt;In the last weeks I&amp;rsquo;ve developed code to load IP reputation information into Suricata. This code is now part of the Suricata git master, so it&amp;rsquo;s available to all.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suricata http_user_agent vs http_header</title>
      <link>https://inliniac.net/blog/2012/07/09/suricata-http_user_agent-vs-http_header/</link>
      <pubDate>Mon, 09 Jul 2012 18:43:12 +0000</pubDate>
      <guid>https://inliniac.net/blog/2012/07/09/suricata-http_user_agent-vs-http_header/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/07/ua-ws.png&#34;&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/07/ua-ws.png?w=300&#34; alt=&#34;&#34;&gt;&lt;/a&gt; One of the new features in Suricata 1.3 is a new content modifier called &lt;em&gt;http_user_agent&lt;/em&gt;. This allows rule writers to match on the User-Agent header in HTTP requests more efficiently. The new keyword is documented in the OISF &lt;a href=&#34;https://redmine.openinfosecfoundation.org/projects/suricata/wiki/HTTP-keywords&#34;&gt;wiki&lt;/a&gt;. In this post, I&amp;rsquo;ll show it&amp;rsquo;s efficiency with two examples.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Example 1: rarely matching UA&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Consider a signature where the match if on a part of the UA that is very rare, so not part of regular User Agents. In my example &amp;ldquo;abc&amp;rdquo;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suricata 1.3 released</title>
      <link>https://inliniac.net/blog/2012/07/06/suricata-1-3-released/</link>
      <pubDate>Fri, 06 Jul 2012 16:06:52 +0000</pubDate>
      <guid>https://inliniac.net/blog/2012/07/06/suricata-1-3-released/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/07/suricata2.png&#34;&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/07/suricata2.png&#34; alt=&#34;&#34;&gt;&lt;/a&gt; Today, almost half a year after the last &amp;ldquo;stable&amp;rdquo; release, we released Suricata 1.3. I think this release is a big step forward with regard to maturity of Suricata. Performance and scalability have been much improved, just like accuracy and stability.&lt;/p&gt;&#xA;&lt;p&gt;The official announcement can be found on the &lt;a href=&#34;http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/157-suricata-13-available&#34;&gt;OISF site&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;In the last 6 months a lot of code has been changed:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;384 files changed, 44332 insertions(+), 18478 deletions(-)&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suricata 1.1 beta 1 released</title>
      <link>https://inliniac.net/blog/2010/12/21/suricata-1-1beta1-released/</link>
      <pubDate>Tue, 21 Dec 2010 17:56:32 +0000</pubDate>
      <guid>https://inliniac.net/blog/2010/12/21/suricata-1-1beta1-released/</guid>
      <description>&lt;p&gt;Today we&amp;rsquo;ve released Suricata 1.1 beta 1, the first beta of the upcoming Suricata 1.1 release. The official release announcement is &lt;a href=&#34;http://openinfosecfoundation.org/index.php/component/content/article/1-latest-news/108-suricata-11-beta-1-released&#34;&gt;here on the OISF website&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The main focus of the new release has been to improve performance and to add support to the features the new ET/ETpro ruleset needs. ET and ETpro have rulesets specially tuned and geared for Suricata. We&amp;rsquo;re still missing some new rule keywords that are used by VRT, so in the 1.1 beta 2 release we&amp;rsquo;ll address that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Setting up Suricata 0.9.0 for initial use on Ubuntu Lucid 10.04</title>
      <link>https://inliniac.net/blog/2010/05/10/setting-up-suricata-0-9-0-for-initial-use-on-ubuntu-lucid-10-04/</link>
      <pubDate>Mon, 10 May 2010 14:27:25 +0000</pubDate>
      <guid>https://inliniac.net/blog/2010/05/10/setting-up-suricata-0-9-0-for-initial-use-on-ubuntu-lucid-10-04/</guid>
      <description>&lt;p&gt;The last few days I blogged about compiling Suricata in &lt;a href=&#34;http://www.inliniac.net/blog/2010/05/07/compiling-suricata-0-9-0-in-ubuntu-lucid-10-04-in-ids-mode.html&#34;&gt;IDS&lt;/a&gt; and &lt;a href=&#34;http://www.inliniac.net/blog/2010/05/07/compiling-suricata-0-9-0-in-ubuntu-lucid-10-04-in-ips-inline-mode.html&#34;&gt;IPS&lt;/a&gt; mode. Today I&amp;rsquo;ll write about how to set it up for first use.&lt;/p&gt;&#xA;&lt;p&gt;Starting with Suricata 0.9.0 the engine can run as an unprivileged user. For this create a new user called &amp;ldquo;suricata&amp;rdquo;.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;useradd &amp;ndash;no-create-home &amp;ndash;shell /bin/false &amp;ndash;user-group &amp;ndash;comment &amp;ldquo;Suricata IDP account&amp;rdquo; suricata&lt;/p&gt;&lt;/blockquote&gt;&#xA;&lt;p&gt;This command will create a user and group called &amp;ldquo;suricata&amp;rdquo;. It will be unable to login as the shell is set to /bin/false.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SidReporter beta2 released</title>
      <link>https://inliniac.net/blog/2008/08/21/sidreporter-beta2-released/</link>
      <pubDate>Thu, 21 Aug 2008 15:08:42 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/08/21/sidreporter-beta2-released/</guid>
      <description>&lt;p&gt;A little over a week ago the second beta of the SidReporter from &lt;a href=&#34;http://www.emergingthreats.net/&#34;&gt;Emerging Threats&lt;/a&gt; was released (see &lt;a href=&#34;http://www.emergingthreats.net/content/view/95/1/&#34;&gt;http://www.emergingthreats.net/content/view/95/1/&lt;/a&gt;). I&amp;rsquo;ve been working with Matt Jonkman to setup this new project at Emerging Threats, mostly in writing the reporter scripts. I think it&amp;rsquo;s an exciting new project that could provide the community with great information. As Matt &lt;a href=&#34;http://www.emergingthreats.net/content/view/93/1/&#34;&gt;wrote&lt;/a&gt; on the initial announcement:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&amp;ldquo;As mentioned a few weeks ago, we&amp;rsquo;ve been working to bring out tool to anonymously report IDS/IPS hits. Similar to DShield&amp;rsquo;s firewall log reporting, we believe we can make some incredible data inferences with this information, as well as help improve the quality of our signatures while giving us all feedback to tune our rulesets.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Snortsam patch for Snort 2.8.0.1</title>
      <link>https://inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801/</link>
      <pubDate>Tue, 08 Jan 2008 12:30:53 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801/</guid>
      <description>&lt;p&gt;Matt Jonkman of &lt;a href=&#34;http://www.emergingthreats.net/&#34;&gt;Emerging Threats&lt;/a&gt; asked me to have a look at the existing Snortsam 2.8.0.1 patch as people were continuing to report problems with it. I updated it to compile without compiler warnings, build cleanly with debugging enabled, build cleanly with Snort&amp;rsquo;s IPv6 support enabled and added a check so it won&amp;rsquo;t act on alerts in IPv6 packets since the Snortsam framework does not support IPv6. Finally I removed the patch script so it&amp;rsquo;s provided as a &amp;rsquo;normal&amp;rsquo; diff. Here is the patch: &lt;a href=&#34;http://www.inliniac.net/files/snortsam-2.8.0.1.diff&#34;&gt;http://www.inliniac.net/files/snortsam-2.8.0.1.diff&lt;/a&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
