The Zeek 8.0 traffic analyzer and Nmap 7.98 network scanner are available.

The release of the Zeek 8.0.0 traffic analysis and network intrusion detection system has been published, previously known as Bro. Zeek is a platform for traffic analysis primarily focused on monitoring security-related events but is not limited to this use. The system's code is written in C++ and is distributed under the BSD license.

The platform provides modules for analyzing and parsing various application layer network protocols, taking into account connection states and allowing detailed logging (archiving) of network activity. It offers a domain-specific language for writing monitoring scripts and detecting anomalies that consider the specifics of particular infrastructures. The system is optimized for use in high-bandwidth networks. An API is provided for integration with third-party information systems and real-time data exchange.

In the new release of Zeek:

  • The ability to configure flow identifiers (Flow Tuple) through plugins has been added. To prevent collisions when splitting flows in complex networks, in addition to (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community., port numbers and protocols, additional context such as VLAN tags or encapsulated traffic identifiers for VXLAN and Geneve can now be considered.
  • A new cluster backend based on ZeroMQ has been made ready for deployment in operational systems, defining the method of interaction between cluster nodes and the format for data serialization. By default, the Broker backend continues to be used, but a transition to the ZeroMQ backend is planned in the future, allowing for the elimination of a proxy when disseminating broadcast messages across nodes. The collection of telemetry regarding cluster operation has been simplified, enabling monitoring of node load, regardless of the backend used.
  • A parser for the Redis database protocol has been added, along with logging of intercepted operations.
  • In the SMTP analyzer, support has been implemented for extracting email messages (RFC 822) from traffic and sending them to the file analyzer, which can be used to save intercepted emails to disk as .eml files.
  • The FTP analyzer now supports the AUTH TLS extension.
  • The DNS analyzer has implemented recognition of NAPTR records.
  • The PPPoE analyzer has been enhanced with the ability to output session identifiers.
  • Instead of separate logs analyzer.log and dpd.log, a single log analyzer.log is now used.
  • The parser generator for protocol and file parsing has been updated to Spicy 1.14, which includes new optimizations and the ability to remove unused function parameters.
  • The format of log recording can now be changed using the logschema package (for example, you can use JSON or CSV instead of traditional text logs).
  • Now, a compiler that supports C++20 is required to build the project. The minimum supported versions are GCC 10, Clang 8, and Visual Studio 2022.

Additionally, the release of the network security scanner Nmap 7.98 is noteworthy, designed for network auditing and identifying active network services. The project's code is provided under the NPSL (Nmap Public Source License), based on the GPLv2 license, which includes recommendations (not requirements) for using OEM licensing and purchasing a commercial license if the manufacturer does not wish to open source their product according to copyleft license requirements or intends to integrate Nmap into products incompatible with GPL.

Version 7.98 of Nmap mainly includes bug fixes. For example, crashes when using nmap with certain VPN-interfaces have been resolved. Among functional changes, NSE bindings have been added for using libssh2 functions in automation scripts with Nmap. The DNS resolver has been optimized. Support for ciphers used in TLSv1.3 has been added to the tls.lua library, including post-quantum cipher suites. Updated versions of OpenSSL 3.0.17, Lua 5.4.8, and Npcap 1.83 have been involved in the builds.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster