{"id":96219,"date":"2020-10-09T13:42:03","date_gmt":"2020-10-09T11:42:03","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vypusk-sistemy-obnaruzheniya-atak-suricata-6-0"},"modified":"2020-10-09T13:42:03","modified_gmt":"2020-10-09T11:42:03","slug":"vypusk-sistemy-obnaruzheniya-atak-suricata-6-0","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-obnaruzheniya-atak-suricata-6-0","title":{"rendered":"Release of the Suricata 6.0 attack detection system","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>After a year of development, the organization OISF (Open Information Security Foundation) <noindex><a rel=\"nofollow\" href=\"https:\/\/suricata-ids.org\/2020\/10\/08\/suricata-6-0-0-released\">released<\/a><\/noindex> release of the intrusion detection and prevention system <noindex><a rel=\"nofollow\" href=\"http:\/\/suricata-ids.org\/\">Suricata 6.0<\/a><\/noindex>, which provides tools for inspecting various types of traffic. In Suricata configurations, it is permissible to engage <noindex><a rel=\"nofollow\" href=\"http:\/\/www.snort.org\/vrt\">signature databases<\/a><\/noindex>, developed by the Snort project, as well as rule sets <noindex><a rel=\"nofollow\" href=\"http:\/\/rules.emergingthreats.net\/\">Emerging Threats<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"http:\/\/rules.emergingthreatspro.com\/\">Emerging Threats Pro<\/a><\/noindex>. The source codes of the project <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/OISF\/suricata\">is distributed<\/a><\/noindex> is licensed under GPLv2. <\/p>\n<p>Key Changes:<\/p>\n<ul>\n<li class=\"l\"> Initial support for HTTP\/2.\n<li class=\"l\"> Support for RFB and MQTT protocols, including protocol detection and logging capability.\n<li class=\"l\"> Logging capability for the DCERPC protocol.\n<li class=\"l\"> Significant performance improvements in logging through the EVE subsystem, which outputs events in JSON format. The acceleration has been achieved by utilizing a new JSON stream builder written in Rust.\n<li class=\"l\"> Increased scalability of the EVE logging system and the implementation of a dedicated log file for each thread.\n<li class=\"l\"> Ability to define conditions for flushing log information.\n<li class=\"l\"> Ability to reflect MAC addresses in the EVE log and increased detail in DNS logging.\n<li class=\"l\"> Enhanced performance of the flow engine.\n<li class=\"l\"> Support for identifying SSH implementations (<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/salesforce\/hassh\">) and DHCP has been added.<\/a><\/noindex>).\n<li class=\"l\"> Implementation of the GENEVE tunnel decoder.\n<li class=\"l\"> The code for processing has been rewritten in Rust <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/ASN.1\">ASN.1<\/a><\/noindex>, DCERPC, and SSH. Support for new protocols has also been implemented in Rust.\n<li class=\"l\"> The rule-definition language has added support for the from_end parameter in the byte_jump keyword, and the bitmask parameter in byte_test. The pcrexform keyword has been implemented, allowing the use of regular expressions (pcre) for substring capturing. URL decoding has been added. The byte_math keyword has been introduced.\n<li class=\"l\"> Providing the ability to use cbindgen for generating bindings in Rust and C languages.\n<li class=\"l\"> Initial support for plugins has been added.\n<\/ul>\n<p>Features of Suricata:\n<\/p>\n<ul>\n<li class=\"l\"> Using a unified format for outputting verification results <noindex><a rel=\"nofollow\" href=\"http:\/\/searchsecuritychannel.techtarget.com\/tip\/0,289483,sid97_gci1339679,00.html\">Unified2<\/a><\/noindex>, which is also used by the Snort project, allows the use of standard analysis tools such as <noindex><a rel=\"nofollow\" href=\"http:\/\/www.securixlive.com\/barnyard2\/index.php\">barnyard2<\/a><\/noindex>. Integration with BASE, Snorby, Sguil, and SQueRT products is possible. Support for output in PCAP format;\n<\/li>\n<li class=\"l\">  Support for automatic protocol detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP, SMB, etc.), allowing operation in rules based solely on the protocol type, without being tied to a port number (for example, blocking HTTP traffic on a non-standard port). There are decoders for HTTP, SSL, TLS, SMB, SMB2, DCERPC, SMTP, FTP, and SSH protocols;\n<\/li>\n<li class=\"l\"> A powerful HTTP traffic analysis system that uses a special library, HTP, created by the author of the Mod_Security project, for parsing and normalizing HTTP traffic. A module for keeping a detailed log of transit HTTP transfers is available, and the log is saved in standard<br \/>\nApache format. The extraction and verification of files transmitted via the HTTP protocol is supported. There is support for parsing compressed content. Identification by URI, Cookie, headers, user-agent, and request\/response body is possible;<\/p>\n<\/li>\n<li class=\"l\"> Support for various interfaces for traffic interception, including NFQueue, IPFRing, LibPcap, IPFW, AF_PACKET, PF_RING. Analysis of already saved files in PCAP format is possible;\n<\/li>\n<li class=\"l\"> High performance, capable of processing streams of up to 10 gigabits\/second on standard hardware.\n<\/li>\n<li class=\"l\"> A high-performance pattern matching mechanism with large sets of IP addresses. Support for content filtering by masks and regular expressions. Extraction of files from traffic, including identification by name, type, or MD5 checksum.\n<\/li>\n<li class=\"l\"> The ability to use variables in rules: you can save information from the stream and later use it in other rules;\n<\/li>\n<li class=\"l\"> Using the YAML format in configuration files, which allows for clarity while being easy for machine processing;\n<\/li>\n<li class=\"l\"> Full support for IPv6;\n<\/li>\n<li class=\"l\"> Built-in engine for automatic defragmentation and reassembly of packets, allowing for correct stream processing, regardless of the order of packet arrival;\n<\/li>\n<li class=\"l\"> Support for tunneling protocols: Teredo, IP-IP, IP6-IP4, IP4-IP6, GRE;\n<\/li>\n<li class=\"l\"> Support for packet decoding: IPv4, IPv6, TCP, UDP, SCTP, ICMPv4, ICMPv6, GRE, Ethernet, PPP, PPPoE, Raw, SLL, VLAN;\n<\/li>\n<li class=\"l\"> Logging mode for keys and certificates involved in TLS\/SSL connections;\n<\/li>\n<li class=\"l\"> The ability to write scripts in Lua for enhanced analysis and implementation of additional features necessary for identifying types of traffic where standard rules are insufficient.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53857\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u0441\u043b\u0435 \u0433\u043e\u0434\u0430 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f OISF (Open Information Security Foundation) \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u043b\u0438\u0437 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u0438 \u043f\u0440\u0435\u0434\u043e\u0442\u0432\u0440\u0430\u0449\u0435\u043d\u0438\u044f \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u0432\u0442\u043e\u0440\u0436\u0435\u043d\u0438\u0439 Suricata 6.0, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0438\u043d\u0441\u043f\u0435\u043a\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0432\u0438\u0434\u043e\u0432 \u0442\u0440\u0430\u0444\u0438\u043a\u0430. \u0412 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 Suricata \u0434\u043e\u043f\u0443\u0441\u0442\u0438\u043c\u043e \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u0438\u0435 \u0431\u0430\u0437\u044b \u0441\u0438\u0433\u043d\u0430\u0442\u0443\u0440, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u043e\u0439 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c Snort, \u0430 \u0442\u0430\u043a\u0436\u0435 \u043d\u0430\u0431\u043e\u0440\u043e\u0432 \u043f\u0440\u0430\u0432\u0438\u043b Emerging Threats \u0438 Emerging Threats Pro. \u0418\u0441\u0445\u043e\u0434\u043d\u044b\u0435 \u0442\u0435\u043a\u0441\u0442\u044b \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u044e\u0442\u0441\u044f \u043f\u043e\u0434 \u043b\u0438\u0446\u0435\u043d\u0437\u0438\u0435\u0439 GPLv2. \u041e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f: [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-96219","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0433\u043e\u0434\u0430 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f OISF (Open Information Security Foundation) \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u043b\u0438\u0437 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-obnaruzheniya-atak-suricata-6-0\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a Suricata 6.0 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0433\u043e\u0434\u0430 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f OISF (Open Information Security Foundation) \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u043b\u0438\u0437 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-obnaruzheniya-atak-suricata-6-0\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-09T11:42:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-09T11:42:03+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Release of the Suricata 6.0 attack detection system | ProHoster","description":"After a year of development, the organization OISF (Open Information Security Foundation) has released the system.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-obnaruzheniya-atak-suricata-6-0","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u044f \u0430\u0442\u0430\u043a Suricata 6.0 | ProHoster","og:description":"\u041f\u043e\u0441\u043b\u0435 \u0433\u043e\u0434\u0430 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u044f OISF (Open Information Security Foundation) \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u043b\u0438\u0437 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-obnaruzheniya-atak-suricata-6-0","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-09T11:42:03+00:00","article:modified_time":"2020-10-09T11:42:03+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"96219","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:48:22","updated":"2022-10-02 08:38:00","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/96219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=96219"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/96219\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=96219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=96219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=96219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}