public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* IDS with support for multiple ruleset providers
@ 2021-04-09 19:27 Stefan Schantl
  2021-04-10 13:01 ` Michael Tremer
                   ` (2 more replies)
  0 siblings, 3 replies; 21+ messages in thread
From: Stefan Schantl @ 2021-04-09 19:27 UTC (permalink / raw)
  To: development

[-- Attachment #1: Type: text/plain, Size: 2150 bytes --]

Hello Development Team and list followers,

there are a lot of different vendors out there which offers different
IDS rules for suricata. Some of them offers a complete set of rules and
other ones some very specialized rules for different tasks.

Unfortunately it only was possible to select only one ruleset provider
at the same time, so it usually wasn't an option to use one of them and
keep a lot of traffic uninspected by the IDS.

Today I'm very happy to announce a testing version of a reworked
Intrusion Detection System which supports the usage of multiple
different providers and rulesets at the same time.

In total up to 15 different ruleset providers now can be used and mixed
together to fit your personal requirements. They easily can be managed
and configured via the WUI. Of course each one individually can be
disabled or re-enabled at each time.

The section for customizing the entire ruleset has been moved to a
subpage, which allows to enable a certain amount of ruleset files or
enabling / disabling single rules inside them.

This helps to speed up the CGI if you want to mange your whitelist,
manage your ruleset providers or change basic settings of your IDS. 

If you liked this short introduction, please help us testing to get
this cool stuff as soon as possible into the core distribution and to
find bugs or other improvements.

The test versions and some screenshots can be found here:

https://people.ipfire.org/~stevee/ids-multiple-providers/

To join testing, please download the latest tarball and place it on
your IPFire test machine.

Execute the archive by using "tar -xvf ids-multiple-providers-
XXX.tar.gz - C /" on your local console or via SSH remote session.

The next steps would be to regenerate the language cache by executing
"update-langs-cache" and to launch "convert-ids-multiple-providers".

The converter will convert all your existing settings into the new
format and also will take care about your used rules and their
settings.

As usual, please report back any kind of feedback on this list and
submit any found bugs to our bugtracker (https://bugs.ipfire.org).

Thanks in advance,

-Stefan



^ permalink raw reply	[flat|nested] 21+ messages in thread

end of thread, other threads:[~2021-04-15 11:08 UTC | newest]

Thread overview: 21+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-04-09 19:27 IDS with support for multiple ruleset providers Stefan Schantl
2021-04-10 13:01 ` Michael Tremer
2021-04-10 17:15   ` Stefan Schantl
2021-04-10 13:06 ` Adolf Belka
2021-04-10 13:15   ` Adolf Belka
2021-04-10 17:18   ` Stefan Schantl
2021-04-10 18:25 ` Stefan Schantl
2021-04-10 20:56   ` Adolf Belka
2021-04-10 21:17     ` Adolf Belka
2021-04-11  6:59       ` Stefan Schantl
2021-04-11  7:07     ` Stefan Schantl
2021-04-11  8:46       ` Stefan Schantl
2021-04-11  9:49         ` Adolf Belka
2021-04-11 10:18           ` Adolf Belka
2021-04-11 12:27             ` Michael Tremer
2021-04-13 18:57             ` Stefan Schantl
2021-04-14  9:12               ` Michael Tremer
2021-04-14 19:01                 ` Stefan Schantl
2021-04-14 19:16               ` Stefan Schantl
2021-04-14 19:25                 ` Stefan Schantl
2021-04-15 11:08                 ` Michael Tremer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox