设为首页收藏本站

LUPA开源社区

 找回密码
 注册
文章 帖子 博客

Suricata 1.1 正式版发布,网络入侵检测

2011-11-13 17:47| 发布者: 红黑魂| 查看: 2978| 评论: 0|来自: 开源中国

摘要: Suricata 是一个网络入侵检测和阻止引擎,由开放信息安全基金会以及它说支持的提供商说开发。该引擎是多线程的,内置 IPv6 的支持,可加载预设规则,支持 Barnyard 和 Barnyard2 工具。Suricata 1.1 版主要改变如下: ...

Suricata 是一个网络入侵检测和阻止引擎,由开放信息安全基金会以及它说支持的提供商说开发。该引擎是多线程的,内置 IPv6 的支持,可加载预设规则,支持 Barnyard 和 Barnyard2 工具。

Suricata 1.1 版主要改变如下:

Notable Improvements

    * performance improvements
    *   – new default pattern matcher
    *   – multi pattern matcher inspection of HTTP buffers
    *   – improved running modes
    * accuracy was greatly improved
    * improved logging
    *   – extended HTTP logging
    *   – support of stream event logging
    * IPS improvements
    *   – inline mode for stream engine
    *   – new keyword and running options for Netfilter based IPS
    * removal of the unified1 output plugins (#353)

New features

    * new keywords ssl_state, ssl_version (#258, #262).
    * support for http_raw_header, http_stat_msg, http_stat_code and http_raw_uri keywords (#259, #260).
    * new keyword support: nfq_set_mark
    * support for suppress keyword was added (#274)
    * byte_extract keyword support was added
    * new default pattern matcher, Aho-Corasick based, that uses much less memory and performs better
    * fast_pattern & multi pattern matching support for HTTP buffers
    * extended HTTP request logging for use with (among other things) http_agent for Sguil (#38)
    * new counters in stats.log for flow and stream engines (#348)
    * AF_PACKET support for high speed packet capture
    * advanced and fine tuning of CPU affinity setting for enhanced multicore performances
    * “replace” keyword support for IPS mode (#303)
    * new “workers” runmode for multi-dev and/or clustered PF_RING, AF_PACKET, pcap
    * added “stream-event” keyword to match on TCP session anomalies
    * Inline mode for the stream engine (#230, #248)
    * Included an example decoder-events.rules file
    * pcap logging / recording output was added
    * basic SCTP protocol parsing was added
    * reference.config support as supplied by ET/ETpro and VRT
    * smtp protocol parser and protocol detection was added
    * better handling of detection for timed out TCP sessions
    * improved protocol detection accuracy with additional support for port based detection

Fixes since 1.1rc1

    * CUDA build fixed
    * minor pcap, AF_PACKET and PF_RING fixes (#368)
    * bpf handling fix
    * Windows CYGWIN build
    * more cleanups

更多关于Suricata的详细信息,或者下载地址请点这里


酷毙
2

雷人

鲜花

鸡蛋

漂亮

刚表态过的朋友 (2 人)

  • 快毕业了,没工作经验,
    找份工作好难啊?
    赶紧去人才芯片公司磨练吧!!

最新评论

关于LUPA|人才芯片工程|人才招聘|LUPA认证|LUPA教育|LUPA开源社区 ( 浙B2-20090187 浙公网安备 33010602006705号   

返回顶部