<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Matt-Jonkman on Inliniac</title>
    <link>https://inliniac.net/blog/tag/matt-jonkman/</link>
    <description>Recent content in Matt-Jonkman on Inliniac</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 29 Nov 2012 16:50:15 +0000</lastBuildDate>
    <atom:link href="https://inliniac.net/blog/tag/matt-jonkman/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Closing in on Suricata 1.4</title>
      <link>https://inliniac.net/blog/2012/11/29/closing-in-on-suricata-1-4/</link>
      <pubDate>Thu, 29 Nov 2012 16:50:15 +0000</pubDate>
      <guid>https://inliniac.net/blog/2012/11/29/closing-in-on-suricata-1-4/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/07/suricata2.png&#34; alt=&#34;&#34;&gt;I just made &lt;a href=&#34;http://suricata-ids.org/2012/11/29/suricata-1-4rc1-available/&#34;&gt;Suricata 1.4rc1&lt;/a&gt; available with some pretty exciting features: unix socket mode and IP reputation.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Unix socket&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;First of all, &lt;a href=&#34;https://home.regit.org/2012/09/a-new-unix-command-mode-in-suricata/&#34;&gt;Eric Leblond&amp;rsquo;s work&lt;/a&gt; on the Unix socket was merged. The unix socket work consists of two parts. The unix socket protocol implementation and a new runmode.&lt;/p&gt;&#xA;&lt;p&gt;The protocol implementation is based on JSON messages over unix socket. Eric will be fully documenting it soon. Currently the commands are limited to shutting down and getting some basic stats. This part isn&amp;rsquo;t very exciting yet, but the groundwork for many future extensions has been laid.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IP Reputation in Suricata</title>
      <link>https://inliniac.net/blog/2012/11/21/ip-reputation-in-suricata/</link>
      <pubDate>Wed, 21 Nov 2012 19:22:01 +0000</pubDate>
      <guid>https://inliniac.net/blog/2012/11/21/ip-reputation-in-suricata/</guid>
      <description>&lt;p&gt;&lt;em&gt;Disclaimer: this work was sponsored by &lt;a href=&#34;http://www.emergingthreatspro.com/&#34;&gt;Emerging Threats Pro&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;One thing we&amp;rsquo;ve been talking about for many years at OISF is IP Reputation. The basic idea is that many organizations have information about specific IP-addresses. This information may be that a host is infected, acts as a spam relay or many other things. We&amp;rsquo;ve always thought it might be useful to apply this info to the IDS directly.&lt;/p&gt;&#xA;&lt;p&gt;In the last weeks I&amp;rsquo;ve developed code to load IP reputation information into Suricata. This code is now part of the Suricata git master, so it&amp;rsquo;s available to all.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DeepSec</title>
      <link>https://inliniac.net/blog/2008/11/30/deepsec/</link>
      <pubDate>Sun, 30 Nov 2008 09:57:42 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/11/30/deepsec/</guid>
      <description>&lt;p&gt;Last month I attended the DeepSec conference in Vienna. I enjoyed it a great deal. It was good to be back in Vienna. Had a few good meetings with my friend Adi with who I work on the Vuurmuur project.&lt;/p&gt;&#xA;&lt;p&gt;I assisted Matt Jonkman in his Snort Signature writing class. We had a nice group of people and using the Emerging Threats SandNet we could deal with pretty interesting samples to write signatures for. Even though my expertise is more on the code level of Snort I felt I could still contribute something to the sessions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>First SidReporter statistics available</title>
      <link>https://inliniac.net/blog/2008/10/30/first-sidreporter-statistics-available/</link>
      <pubDate>Thu, 30 Oct 2008 15:11:37 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/10/30/first-sidreporter-statistics-available/</guid>
      <description>&lt;p&gt;Matt Jonkman just &lt;a href=&#34;http://www.emergingthreats.net/index.php/component/content/article/1-latest/127-initial-sidreporter-statistics-online.html&#34;&gt;announced&lt;/a&gt; that the first stats of SidReporter are available &lt;a href=&#34;http://www.emergingthreats.net/index.php/sidreporter-statistics.html&#34;&gt;here&lt;/a&gt;. Matt writes:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;These will become more interesting the more sites we have reporting, so please consider running  the client. It&amp;rsquo;s painless, anonymous, and will contribute to us greatly improving the signature base we all use.&lt;/p&gt;&lt;/blockquote&gt;&#xA;&lt;p&gt;It will be interesting to see what data this can bring us. Congrats Matt!&lt;/p&gt;</description>
    </item>
    <item>
      <title>First OISF brainstorming session on Deepsec</title>
      <link>https://inliniac.net/blog/2008/10/23/first-oisf-brainstorming-session-on-deepsec/</link>
      <pubDate>Thu, 23 Oct 2008 09:02:21 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/10/23/first-oisf-brainstorming-session-on-deepsec/</guid>
      <description>&lt;p&gt;Next November I will be attending &lt;a href=&#34;http://deepsec.net&#34;&gt;Deepsec&lt;/a&gt; in Vienna. Matt Jonkman is giving a workshop there and I will be helping/assisting him with it, it&amp;rsquo;s called &amp;lsquo;Protocol Analysis for Writing Snort Signatures&amp;rsquo;. If you&amp;rsquo;re interested, sign up for it! While we are there we will also host the first brainstorming session for &lt;a href=&#34;http://www.openinfosecfoundation.org/&#34;&gt;OISF&lt;/a&gt;. The idea is to get together with everyone thats interested and talk about how our next generation IDS/IPS should look like. But it&amp;rsquo;s not just about the technology, we also seek input about how to organize the project, about licensing, etc. So if you&amp;rsquo;re at Deepsec and got some time to spare, be sure to join us in the brainstorming session!&lt;/p&gt;</description>
    </item>
    <item>
      <title>SidReporter beta2 released</title>
      <link>https://inliniac.net/blog/2008/08/21/sidreporter-beta2-released/</link>
      <pubDate>Thu, 21 Aug 2008 15:08:42 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/08/21/sidreporter-beta2-released/</guid>
      <description>&lt;p&gt;A little over a week ago the second beta of the SidReporter from &lt;a href=&#34;http://www.emergingthreats.net/&#34;&gt;Emerging Threats&lt;/a&gt; was released (see &lt;a href=&#34;http://www.emergingthreats.net/content/view/95/1/&#34;&gt;http://www.emergingthreats.net/content/view/95/1/&lt;/a&gt;). I&amp;rsquo;ve been working with Matt Jonkman to setup this new project at Emerging Threats, mostly in writing the reporter scripts. I think it&amp;rsquo;s an exciting new project that could provide the community with great information. As Matt &lt;a href=&#34;http://www.emergingthreats.net/content/view/93/1/&#34;&gt;wrote&lt;/a&gt; on the initial announcement:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&amp;ldquo;As mentioned a few weeks ago, we&amp;rsquo;ve been working to bring out tool to anonymously report IDS/IPS hits. Similar to DShield&amp;rsquo;s firewall log reporting, we believe we can make some incredible data inferences with this information, as well as help improve the quality of our signatures while giving us all feedback to tune our rulesets.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Snortsam patch for Snort 2.8.0.1</title>
      <link>https://inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801/</link>
      <pubDate>Tue, 08 Jan 2008 12:30:53 +0000</pubDate>
      <guid>https://inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801/</guid>
      <description>&lt;p&gt;Matt Jonkman of &lt;a href=&#34;http://www.emergingthreats.net/&#34;&gt;Emerging Threats&lt;/a&gt; asked me to have a look at the existing Snortsam 2.8.0.1 patch as people were continuing to report problems with it. I updated it to compile without compiler warnings, build cleanly with debugging enabled, build cleanly with Snort&amp;rsquo;s IPv6 support enabled and added a check so it won&amp;rsquo;t act on alerts in IPv6 packets since the Snortsam framework does not support IPv6. Finally I removed the patch script so it&amp;rsquo;s provided as a &amp;rsquo;normal&amp;rsquo; diff. Here is the patch: &lt;a href=&#34;http://www.inliniac.net/files/snortsam-2.8.0.1.diff&#34;&gt;http://www.inliniac.net/files/snortsam-2.8.0.1.diff&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Matt Jonkman leaves Bleeding Edge</title>
      <link>https://inliniac.net/blog/2007/11/17/matt-jonkman-leaves-bleeding-edge/</link>
      <pubDate>Sat, 17 Nov 2007 12:05:56 +0000</pubDate>
      <guid>https://inliniac.net/blog/2007/11/17/matt-jonkman-leaves-bleeding-edge/</guid>
      <description>&lt;p&gt;Matt Jonkman is stepping out of the &lt;a href=&#34;http://www.bleedingthreats.net/&#34;&gt;Bleeding Edge project&lt;/a&gt;. He announced this &lt;a href=&#34;http://www.bleedingthreats.net/index.php/2007/11/17/im-leaving-bleeding-threats/&#34;&gt;here&lt;/a&gt;. Apparently &lt;a href=&#34;http://sensorynetworks.com/&#34;&gt;Sensory Networks&lt;/a&gt;, one of the sponsors of the project, now owns it. It will be interesting to see if they will continue it, and if so, how. Honestly, I&amp;rsquo;m a bit skeptical, since to my knowledge not many Sensory people are directly involved at this moment. Still I believe Sensory consists of good people. I did a contract job for them about a year ago, and enjoyed working with them.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
