<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Suricata on Inliniac</title>
    <link>https://inliniac.net/blog/tag/suricata/</link>
    <description>Recent content in Suricata on Inliniac</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sun, 24 Feb 2019 19:22:51 +0000</lastBuildDate>
    <atom:link href="https://inliniac.net/blog/tag/suricata/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Vuurmuur 0.8 has been released</title>
      <link>https://inliniac.net/blog/2019/02/24/vuurmuur-0-8-has-been-released/</link>
      <pubDate>Sun, 24 Feb 2019 19:22:51 +0000</pubDate>
      <guid>https://inliniac.net/blog/2019/02/24/vuurmuur-0-8-has-been-released/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve just pushed the 0.8 release. See my announcement &lt;a href=&#34;https://sourceforge.net/p/vuurmuur/mailman/message/36591637/&#34;&gt;here&lt;/a&gt;. Get it from &lt;a href=&#34;https://github.com/inliniac/vuurmuur/releases/tag/0.8&#34;&gt;github&lt;/a&gt; or the &lt;a href=&#34;ftp://ftp.vuurmuur.org/releases/0.8/&#34;&gt;ftp&lt;/a&gt; &lt;a href=&#34;ftp://ftp.vuurmuur.org/releases/0.8/&#34;&gt;server&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Largest changes:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;ipv6 support using ip6tables&lt;/li&gt;&#xA;&lt;li&gt;logging uses nflog - initial work by Fred Leeflang&lt;/li&gt;&#xA;&lt;li&gt;connection logging and viewer&lt;/li&gt;&#xA;&lt;li&gt;add rpfilter and improved helper support&lt;/li&gt;&#xA;&lt;li&gt;a &amp;lsquo;dialog&amp;rsquo; based setup wizard&lt;/li&gt;&#xA;&lt;li&gt;single code base / package&lt;/li&gt;&#xA;&lt;li&gt;massive code cleanup&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;I plan to continue to work on Vuurmuur, but it will likely remain at a low pace. Suricata development is simply taking too much of my time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SMTP file extraction in Suricata</title>
      <link>https://inliniac.net/blog/2014/11/11/smtp-file-extraction-in-suricata/</link>
      <pubDate>Tue, 11 Nov 2014 10:47:42 +0000</pubDate>
      <guid>https://inliniac.net/blog/2014/11/11/smtp-file-extraction-in-suricata/</guid>
      <description>&lt;p&gt;In &lt;a href=&#34;http://suricata-ids.org/2014/11/06/suricata-2-1beta2-available/&#34;&gt;2.1beta2&lt;/a&gt; the long awaited SMTP file extraction support for Suricata finally appeared. It has been a long development cycle. Originally started by BAE Systems, it was picked up by Tom Decanio of FireEye Forensics Group (formerly nPulse Technologies) followed by a last round of changes from my side. But it&amp;rsquo;s here now.&lt;/p&gt;&#xA;&lt;p&gt;It contains:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;a MIME decoder&lt;/li&gt;&#xA;&lt;li&gt;updates to the SMTP parser to use the MIME decoder for extracting files&lt;/li&gt;&#xA;&lt;li&gt;SMTP JSON log, integrated with EVE&lt;/li&gt;&#xA;&lt;li&gt;SMTP message URL extraction and logging&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As it uses the Suricata file handling API, it shares almost everything with the existing file handling for HTTP. The rule keyword work and the various logs work automatically with SMTP as well.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suricata http_user_agent vs http_header</title>
      <link>https://inliniac.net/blog/2012/07/09/suricata-http_user_agent-vs-http_header/</link>
      <pubDate>Mon, 09 Jul 2012 18:43:12 +0000</pubDate>
      <guid>https://inliniac.net/blog/2012/07/09/suricata-http_user_agent-vs-http_header/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/07/ua-ws.png&#34;&gt;&lt;img src=&#34;https://inliniac.net/blog/blog/wp-content/uploads/2012/07/ua-ws.png?w=300&#34; alt=&#34;&#34;&gt;&lt;/a&gt; One of the new features in Suricata 1.3 is a new content modifier called &lt;em&gt;http_user_agent&lt;/em&gt;. This allows rule writers to match on the User-Agent header in HTTP requests more efficiently. The new keyword is documented in the OISF &lt;a href=&#34;https://redmine.openinfosecfoundation.org/projects/suricata/wiki/HTTP-keywords&#34;&gt;wiki&lt;/a&gt;. In this post, I&amp;rsquo;ll show it&amp;rsquo;s efficiency with two examples.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Example 1: rarely matching UA&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Consider a signature where the match if on a part of the UA that is very rare, so not part of regular User Agents. In my example &amp;ldquo;abc&amp;rdquo;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
