After six months of development, Cisco has released Snort 2.9.13.0, a free intrusion detection and prevention system that combines signature matching methods, protocol inspection tools, and anomaly detection mechanisms.
Key innovations:
- Support for reloading rules after their update has been added;
- A scenario for adding packets to the blacklist has been implemented, ensuring that a new session will be allowed;
- A new preprocessor warning for incorrect HTTP header termination has been addressed;
- The hash calculation for files transferred via FTP/HTTP has been modified to indicate an offset;
- A problem with hanging connections on authentication requests in a half-closed state has been resolved;
- The timeout for UDP packets sent to non-standard network ports has been changed.
Source: opennet.ru
