ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 2: ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืจืืฉื•ื ื™ืช ืฉืœ Suricata

ืœืคื™ ื”ืกื˜ื˜ื™ืกื˜ื™ืงื”, ื ืคื— ื”ืชืขื‘ื•ืจื” ื‘ืจืฉืช ื’ื“ืœ ื‘ื›-50% ืžื“ื™ ืฉื ื”. ื–ื” ืžื•ื‘ื™ืœ ืœืขืœื™ื™ื” ื‘ืขื•ืžืก ืขืœ ื”ืฆื™ื•ื“ ื•ื‘ืžื™ื•ื—ื“ ืžื’ื“ื™ืœ ืืช ื“ืจื™ืฉื•ืช ื”ื‘ื™ืฆื•ืขื™ื ืฉืœ IDS โ€‹โ€‹/ IPS. ืืชื” ื™ื›ื•ืœ ืœืงื ื•ืช ื—ื•ืžืจื” ืžื™ื•ื—ื“ืช ื•ื™ืงืจื”, ืื‘ืœ ื™ืฉ ืืคืฉืจื•ืช ื–ื•ืœื” ื™ื•ืชืจ - ื”ื›ื ืกืช ืื—ืช ืžืžืขืจื›ื•ืช ื”ืงื•ื“ ื”ืคืชื•ื—. ืžื ื”ืœื™ ืžืขืจื›ืช ืžืชื—ื™ืœื™ื ืจื‘ื™ื ืžืชืงืฉื™ื ืœื”ืชืงื™ืŸ ื•ืœื”ื’ื“ื™ืจ IPS ื‘ื—ื™ื ื. ื‘ืžืงืจื” ืฉืœ Suricata, ื–ื” ืœื ืœื’ืžืจื™ ื ื›ื•ืŸ - ืืชื” ื™ื›ื•ืœ ืœื”ืชืงื™ืŸ ืืช ื–ื” ื•ืœื”ืชื—ื™ืœ ืœื”ื“ื•ืฃ ื”ืชืงืคื•ืช ืื•ืคื™ื™ื ื™ื•ืช ืขื ืกื˜ ื—ื•ืงื™ื ื—ื™ื ืžื™ื™ื ืชื•ืš ืžืกืคืจ ื“ืงื•ืช.

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 2: ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืจืืฉื•ื ื™ืช ืฉืœ Suricata
ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 1: ื‘ื—ื™ืจืช IDS/IPS ื‘ื—ื™ื ื ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ื”ืจืฉืช ื”ืืจื’ื•ื ื™ืช ืฉืœืš

ืœืžื” ืื ื—ื ื• ืฆืจื™ื›ื™ื ืขื•ื“ IPS ืคืชื•ื—?

ื–ืžืŸ ืจื‘ ืฉื ื—ืฉื‘ ืœืกื˜ื ื“ืจื˜, Snort ื ืžืฆื ื‘ืคื™ืชื•ื— ืžืื– ืกื•ืฃ ืฉื ื•ืช ื”ืชืฉืขื™ื, ืื– ื–ื” ื”ื™ื” ื‘ืžืงื•ืจ ืขื ื—ื•ื˜ ื™ื—ื™ื“. ื‘ืžื”ืœืš ื”ืฉื ื™ื ื”ื•ืคื™ืขื• ื‘ื• ื›ืœ ื”ืคื™ืฆ'ืจื™ื ื”ืžื•ื“ืจื ื™ื™ื, ื›ืžื• ืชืžื™ื›ื” ื‘-IPv6, ื”ื™ื›ื•ืœืช ืœื ืชื— ืคืจื•ื˜ื•ืงื•ืœื™ื ื‘ืจืžืช ื”ืืคืœื™ืงืฆื™ื” ืื• ืžื•ื“ื•ืœ ื’ื™ืฉื” ืื•ื ื™ื‘ืจืกืœื™ ืœื ืชื•ื ื™ื.

ืžื ื•ืข ื”ืœื™ื‘ื” Snort 2.X ืœืžื“ ืœืขื‘ื•ื“ ืขื ืœื™ื‘ื•ืช ืžืจื•ื‘ื•ืช, ืืš ื ืฉืืจ ืขื ืคืชื™ืœ ื‘ื•ื“ื“ ื•ืœื›ืŸ ืื™ื ื• ื™ื›ื•ืœ ืœื ืฆืœ ื‘ืฆื•ืจื” ืžื™ื˜ื‘ื™ืช ืืช ืคืœื˜ืคื•ืจืžื•ืช ื”ื—ื•ืžืจื” ื”ืžื•ื“ืจื ื™ื•ืช.

ื”ื‘ืขื™ื” ื ืคืชืจื” ื‘ื’ืจืกื” ื”ืฉืœื™ืฉื™ืช ืฉืœ ื”ืžืขืจื›ืช, ืื‘ืœ ืœืงื— ื›ืœ ื›ืš ื”ืจื‘ื” ื–ืžืŸ ืœื”ืชื›ื•ื ืŸ ืขื“ ืฉ-Suricata, ืฉื ื›ืชื‘ื” ืžืืคืก, ื”ืฆืœื™ื—ื” ืœื”ื•ืคื™ืข ื‘ืฉื•ืง. ื‘-2009 ื”ื—ืœื• ืœืคืชื— ืื•ืชื• ื“ื•ื•ืงื ื›ื—ืœื•ืคื” ืžืจื•ื‘ืช ื”ืœื™ื›ื™ ืฉืจืฉืจืช ืœ-Snort, ืฉื™ืฉ ืœื” ืคื•ื ืงืฆื™ื•ืช IPS ืžื—ื•ืฅ ืœืงื•ืคืกื”. ื”ืงื•ื“ ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ GPLv2, ืืš ืœืฉื•ืชืคื™ื ื”ืคื™ื ื ืกื™ื™ื ืฉืœ ื”ืคืจื•ื™ืงื˜ ื™ืฉ ื’ื™ืฉื” ืœื’ืจืกื” ืกื’ื•ืจื” ืฉืœ ื”ืžื ื•ืข. ื›ืžื” ื‘ืขื™ื•ืช ืžื“ืจื’ื™ื•ืช ื”ืชืขื•ืจืจื• ื‘ื’ืจืกืื•ืช ื”ืจืืฉื•ื ื•ืช ืฉืœ ื”ืžืขืจื›ืช, ืืš ื”ืŸ ื ืคืชืจื• ื‘ืžื”ื™ืจื•ืช.

ืœืžื” ืกื•ืจื™ืงื”?

ืœ-Suricata ื™ืฉ ืžืกืคืจ ืžื•ื“ื•ืœื™ื (ื‘ื“ื•ืžื” ืœ-Snort): ืœื›ื™ื“ื”, ืœื›ื™ื“ื”, ืคืขื ื•ื—, ื–ื™ื”ื•ื™ ื•ืคืœื˜. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ืชืขื‘ื•ืจื” ืฉื ืœื›ื“ื” ืขื•ื‘ืจืช ืœืคื ื™ ื”ืคืขื ื•ื— ื‘ื–ืจื ืื—ื“, ืื ื›ื™ ื–ื” ื˜ื•ืขืŸ ืืช ื”ืžืขืจื›ืช ื™ื•ืชืจ. ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ื ื™ืชืŸ ืœื—ืœืง ืฉืจืฉื•ืจื™ื ื‘ื”ื’ื“ืจื•ืช ื•ืœื”ืคื™ืฅ ื‘ื™ืŸ ื”ืžืขื‘ื“ื™ื - Suricata ืžื•ืชืืžืช ื”ื™ื˜ื‘ ืœื—ื•ืžืจื” ืกืคืฆื™ืคื™ืช, ืื ื›ื™ ื–ื• ื›ื‘ืจ ืœื ืจืžืช HOWTO ืœืžืชื—ื™ืœื™ื. ื›ืžื• ื›ืŸ, ืจืื•ื™ ืœืฆื™ื™ืŸ ื›ื™ ืœ-Suricata ื™ืฉ ื›ืœื™ ื‘ื“ื™ืงืช HTTP ืžืชืงื“ืžื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ืกืคืจื™ื™ืช HTP. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื’ื ืœืชื™ืขื•ื“ ืชืขื‘ื•ืจื” ืœืœื ื–ื™ื”ื•ื™. ื”ืžืขืจื›ืช ืชื•ืžื›ืช ื’ื ื‘ืคืขื ื•ื— IPv6, ื›ื•ืœืœ ืžื ื”ืจื•ืช IPv4-in-IPv6, ืžื ื”ืจื•ืช IPv6-in-IPv6 ื•ืขื•ื“.

ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืžืžืฉืงื™ื ืฉื•ื ื™ื ืœื™ื™ืจื˜ ืชืขื‘ื•ืจื” (NFQueue, IPFRing, LibPcap, IPFW, AF_PACKET, PF_RING), ื•ื‘ืžืฆื‘ Unix Socket, ื ื™ืชืŸ ืœื ืชื— ืื•ื˜ื•ืžื˜ื™ืช ืงื‘ืฆื™ PCAP ืฉื ืœื›ื“ื• ืขืœ ื™ื“ื™ ืจื—ืจื— ืื—ืจ. ื‘ื ื•ืกืฃ, ื”ืืจื›ื™ื˜ืงื˜ื•ืจื” ื”ืžื•ื“ื•ืœืจื™ืช ืฉืœ Suricata ืžืงืœื” ืขืœ ื—ื™ื‘ื•ืจ ืืœืžื ื˜ื™ื ื—ื“ืฉื™ื ืœืœื›ื™ื“ื”, ืคืขื ื•ื—, ื ื™ืชื•ื— ื•ืขื™ื‘ื•ื“ ืžื ื•ืช ืจืฉืช. ื›ืžื• ื›ืŸ, ื—ืฉื•ื‘ ืœืฆื™ื™ืŸ ืฉื‘ืกื•ืจื™ืงื˜ื” ื—ืกื™ืžืช ื”ืชืขื‘ื•ืจื” ื‘ืืžืฆืขื•ืช ืคื™ืœื˜ืจ ืจื’ื™ืœ ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื”. ืœ-GNU/Linux ื™ืฉ ืฉืชื™ ืืคืฉืจื•ื™ื•ืช ืœืื•ืคืŸ ื”ืคืขื•ืœื” ืฉืœ IPS: ื“ืจืš ืชื•ืจ NFQUEUE (ืžืฆื‘ NFQ) ื•ื“ืจืš ื”ืขืชืงื” ืืคืก (ืžืฆื‘ AF_PACKET). ื‘ืžืงืจื” ื”ืจืืฉื•ืŸ, ื”ื—ื‘ื™ืœื” ืฉื ื›ื ืกืช ืœ-iptables ื ืฉืœื—ืช ืœืชื•ืจ NFQUEUE, ืฉื ื ื™ืชืŸ ืœืขื‘ื“ ืื•ืชื” ื‘ืจืžืช ื”ืžืฉืชืžืฉ. Suricata ืžืคืขื™ืœ ืื•ืชื• ืœืคื™ ื”ื›ืœืœื™ื ืฉืœื” ื•ืžื•ืฆื™ื ืื—ื“ ืžืฉืœื•ืฉืช ืคืกืงื™ ื“ื™ืŸ: NF_ACCEPT, NF_DROP ื•-NF_REPEAT. ื”ืฉืชื™ื™ื ื”ืจืืฉื•ื ื•ืช ืžื•ื‘ื ื•ืช ืžืืœื™ื”ืŸ, ื‘ืขื•ื“ ืฉื”ืื—ืจื•ืŸ ืžืืคืฉืจ ืœืชื™ื™ื’ ืžื ื•ืช ื•ืœืฉืœื•ื— ืœืจืืฉ ื˜ื‘ืœืช iptables ื”ื ื•ื›ื—ื™ืช. ืžืฆื‘ AF_PACKET ืžื”ื™ืจ ื™ื•ืชืจ, ืืš ื”ื•ื ืžื˜ื™ืœ ืžืกืคืจ ื”ื’ื‘ืœื•ืช ืขืœ ื”ืžืขืจื›ืช: ืขืœื™ื• ืœื”ื™ื•ืช ื‘ืขืœ ืฉื ื™ ืžืžืฉืงื™ ืจืฉืช ื•ืœืขื‘ื•ื“ ื›ืฉืขืจ. ื”ื—ื‘ื™ืœื” ื”ื—ืกื•ืžื” ืคืฉื•ื˜ ืœื ืžื•ืขื‘ืจืช ืœืžืžืฉืง ื”ืฉื ื™.

ืชื›ื•ื ื” ื—ืฉื•ื‘ื” ืฉืœ Suricata ื”ื™ื ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืคื™ืชื•ื—ื™ื ืขื‘ื•ืจ Snort. ืœืžื ื”ืœ ื”ืžืขืจื›ืช ื™ืฉ ื’ื™ืฉื”, ื‘ืžื™ื•ื—ื“, ืœืžืขืจื›ื•ืช ื”ื›ืœืœื™ื ืฉืœ Sourcefire VRT ื•-OpenSource Emerging Threats, ื›ืžื• ื’ื ืœ-Emerging Threats Pro ื”ืžืกื—ืจื™. ื ื™ืชืŸ ืœื ืชื— ืืช ื”ืคืœื˜ ื”ืžืื•ื—ื“ ื‘ืืžืฆืขื•ืช ืงืฆื” ืื—ื•ืจื™ ืคื•ืคื•ืœืจื™, ืคืœื˜ PCAP ื•-Syslog ื ืชืžืš ื’ื ื›ืŸ. ื”ื’ื“ืจื•ืช ื•ื›ืœืœื™ ืžืขืจื›ืช ืžืื•ื—ืกื ื™ื ื‘ืงื‘ืฆื™ YAML, ืฉืงืœ ืœืงืจื•ื ืื•ืชื ื•ื ื™ืชื ื™ื ืœืขื™ื‘ื•ื“ ืื•ื˜ื•ืžื˜ื™. ืžื ื•ืข Suricata ืžื–ื”ื” ืคืจื•ื˜ื•ืงื•ืœื™ื ืจื‘ื™ื, ื›ืš ืฉื”ื›ืœืœื™ื ืื™ื ื ืฆืจื™ื›ื™ื ืœื”ื™ื•ืช ืงืฉื•ืจื™ื ืœืžืกืคืจ ื™ืฆื™ืื”. ื‘ื ื•ืกืฃ, ื”ืจืขื™ื•ืŸ ืฉืœ flowbits ืžืชื•ืจื’ืœ ื‘ืื•ืคืŸ ืคืขื™ืœ ื‘ื›ืœืœื™ Suricata. ื›ื“ื™ ืœืขืงื•ื‘ ืื—ืจ ื”ื˜ืจื™ื’ืจ, ืžืฉืชื ื™ ื”ืคืขืœื” ืžืฉืžืฉื™ื ืœื™ืฆื™ืจื” ื•ื”ื—ืœื” ืฉืœ ืžื•ื ื™ื ื•ื“ื’ืœื™ื ืฉื•ื ื™ื. IDS ืจื‘ื™ื ืžืชื™ื™ื—ืกื™ื ืœื—ื™ื‘ื•ืจื™ TCP ืฉื•ื ื™ื ื›ืืœ ื™ืฉื•ื™ื•ืช ื ืคืจื“ื•ืช ื•ื™ื™ืชื›ืŸ ืฉืœื ื™ืจืื• ืงืฉืจ ื‘ื™ื ื™ื”ื ื”ืžืขื™ื“ ืขืœ ืชื—ื™ืœืชื” ืฉืœ ื”ืชืงืคื”. Suricata ืžื ืกื” ืœืจืื•ืช ืืช ื›ืœ ื”ืชืžื•ื ื” ื•ื‘ืžืงืจื™ื ืจื‘ื™ื ืžื–ื”ื” ืชืขื‘ื•ืจื” ื–ื“ื•ื ื™ืช ื”ืžื•ืคืฆืช ืขืœ ืคื ื™ ื—ื™ื‘ื•ืจื™ื ืฉื•ื ื™ื. ืืคืฉืจ ืœื“ื‘ืจ ืขืœ ื”ื™ืชืจื•ื ื•ืช ืฉืœื• ื”ืจื‘ื” ื–ืžืŸ, ืžื•ื˜ื‘ ืฉื ืขื‘ื•ืจ ืœื”ืชืงื ื” ื•ืชืฆื•ืจื”.

ื›ื™ืฆื“ ืœื”ืชืงื™ืŸ?

ื ืชืงื™ืŸ ืืช Suricata ืขืœ ืฉืจืช ื•ื™ืจื˜ื•ืืœื™ ืฉืžืจื™ืฅ ืื•ื‘ื•ื ื˜ื• 18.04 LTS. ื™ืฉ ืœื‘ืฆืข ืืช ื›ืœ ื”ืคืงื•ื“ื•ืช ื‘ืฉื ืžืฉืชืžืฉ ื”ืขืœ (ืฉื•ืจืฉ). ื”ืืคืฉืจื•ืช ื”ืžืื•ื‘ื˜ื—ืช ื‘ื™ื•ืชืจ ื”ื™ื ืœื”ื›ื ื™ืก SSH ืœืฉืจืช ื›ืžืฉืชืžืฉ ืจื’ื™ืœ ื•ืœืื—ืจ ืžื›ืŸ ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ ื”ืขื–ืจ sudo ื›ื“ื™ ืœื”ืขืœื•ืช ื”ืจืฉืื•ืช. ืจืืฉื™ืช ืขืœื™ืš ืœื”ืชืงื™ืŸ ืืช ื”ื—ื‘ื™ืœื•ืช ืฉืื ื• ืฆืจื™ื›ื™ื:

sudo apt -y install libpcre3 libpcre3-dev build-essential autoconf automake libtool libpcap-dev libnet1-dev libyaml-0-2 libyaml-dev zlib1g zlib1g-dev libmagic-dev libcap-ng-dev libjansson-dev pkg-config libnetfilter-queue-dev geoip-bin geoip-database geoipupdate apt-transport-https

ื—ื™ื‘ื•ืจ ืžืื’ืจ ื—ื™ืฆื•ื ื™:

sudo add-apt-repository ppa:oisf/suricata-stable
sudo apt-get update

ื”ืชืงืŸ ืืช ื”ื’ืจืกื” ื”ื™ืฆื™ื‘ื” ื”ืื—ืจื•ื ื” ืฉืœ Suricata:

sudo apt-get install suricata

ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืขืจื•ืš ืืช ืฉื ืงื‘ืฆื™ ื”ืชืฆื•ืจื”, ืชื•ืš ื”ื—ืœืคืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ eth0 ื‘ืฉื ื”ืืžื™ืชื™ ืฉืœ ื”ืžืžืฉืง ื”ื—ื™ืฆื•ื ื™ ืฉืœ ื”ืฉืจืช. ื”ื’ื“ืจื•ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืžืื•ื—ืกื ื•ืช ื‘ืงื•ื‘ืฅ /etc/default/suricata, ื•ื”ื’ื“ืจื•ืช ืžื•ืชืืžื•ืช ืื™ืฉื™ืช ืžืื•ื—ืกื ื•ืช ื‘- /etc/suricata/suricata.yaml. ื”ื’ื“ืจืช IDS ืžื•ื’ื‘ืœืช ื‘ืขื™ืงืจ ืœืขืจื™ื›ืช ืงื•ื‘ืฅ ืชืฆื•ืจื” ื–ื”. ื™ืฉ ืœื• ื”ืจื‘ื” ืคืจืžื˜ืจื™ื, ืœืคื™ ื”ืฉื ื•ื”ืžื˜ืจื”, ื—ื•ืคืคื™ื ืœืื ืœื•ื’ื™ื ืฉืœ Snort. ืขื ื–ืืช, ื”ืชื—ื‘ื™ืจ ืฉื•ื ื” ืœืžื“ื™, ืื‘ืœ ื”ืงื•ื‘ืฅ ื”ืจื‘ื” ื™ื•ืชืจ ืงืœ ืœืงืจื™ืื” ืžืืฉืจ ืชืฆื•ืจื•ืช Snort, ื•ื”ื•ื ืžืงื‘ืœ ื”ืขืจื•ืช ื˜ื•ื‘ื•ืช.

sudo nano /etc/default/suricata

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 2: ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืจืืฉื•ื ื™ืช ืฉืœ Suricata

ะธ

sudo nano /etc/suricata/suricata.yaml

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 2: ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืจืืฉื•ื ื™ืช ืฉืœ Suricata

ืชืฉื•ืžืช ื”ืœื‘! ืœืคื ื™ ืฉืžืชื—ื™ืœื™ื, ื›ื“ืื™ ืœื‘ื“ื•ืง ืืช ืขืจื›ื™ ื”ืžืฉืชื ื™ื ืžืงื˜ืข vars.

ื›ื“ื™ ืœื”ืฉืœื™ื ืืช ื”ื”ื’ื“ืจื”, ืชืฆื˜ืจืš ืœื”ืชืงื™ืŸ ืืช suricata-update ื›ื“ื™ ืœืขื“ื›ืŸ ื•ืœื˜ืขื•ืŸ ืืช ื”ื›ืœืœื™ื. ื–ื” ื“ื™ ืงืœ ืœืขืฉื•ืช ืืช ื–ื”:

sudo apt install python-pip
sudo pip install pyyaml
sudo pip install <a href="https://github.com/OISF/suricata-update/archive/master.zip">https://github.com/OISF/suricata-update/archive/master.zip</a>
sudo pip install --pre --upgrade suricata-update

ืœืื—ืจ ืžื›ืŸ, ืขืœื™ื ื• ืœื”ืคืขื™ืœ ืืช ื”ืคืงื•ื“ื” suricata-update ื›ื“ื™ ืœื”ืชืงื™ืŸ ืืช ืขืจื›ืช ื”ื›ืœืœื™ื ืฉืœ Emerging Threats Open:

sudo suricata-update

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 2: ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืจืืฉื•ื ื™ืช ืฉืœ Suricata

ื›ื“ื™ ืœื”ืฆื™ื’ ืืช ืจืฉื™ืžืช ืžืงื•ืจื•ืช ื”ื›ืœืœื™ื, ื”ืคืขืœ ืืช ื”ืคืงื•ื“ื” ื”ื‘ืื”:

sudo suricata-update list-sources

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 2: ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืจืืฉื•ื ื™ืช ืฉืœ Suricata

ืขื“ื›ื•ืŸ ืžืงื•ืจื•ืช ื›ืœืœื™ื:

sudo suricata-update update-sources

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 2: ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืจืืฉื•ื ื™ืช ืฉืœ Suricata

ื‘ื™ืงื•ืจ ื—ื•ื–ืจ ื‘ืžืงื•ืจื•ืช ืžืขื•ื“ื›ื ื™ื:

sudo suricata-update list-sources

ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืชื•ื›ืœ ืœื›ืœื•ืœ ืžืงื•ืจื•ืช ื–ืžื™ื ื™ื ื‘ื—ื™ื ื:

sudo suricata-update enable-source ptresearch/attackdetection
sudo suricata-update enable-source oisf/trafficid
sudo suricata-update enable-source sslbl/ssl-fp-blacklist

ืœืื—ืจ ืžื›ืŸ, ืขืœื™ืš ืœืขื“ื›ืŸ ืฉื•ื‘ ืืช ื”ื›ืœืœื™ื:

sudo suricata-update

ื–ื” ืžืฉืœื™ื ืืช ื”ื”ืชืงื ื” ื•ื”ืชืฆื•ืจื” ื”ืจืืฉื•ื ื™ืช ืฉืœ Suricata ื‘ืื•ื‘ื•ื ื˜ื• 18.04 LTS. ื•ืื– ืžืชื—ื™ืœ ื”ื›ื™ืฃ: ื‘ืžืืžืจ ื”ื‘ื ื ื—ื‘ืจ ืฉืจืช ื•ื™ืจื˜ื•ืืœื™ ืœืจืฉืช ื”ืžืฉืจื“ื™ืช ื‘ืืžืฆืขื•ืช VPN ื•ื ืชื—ื™ืœ ืœื ืชื— ืืช ื›ืœ ื”ืชืขื‘ื•ืจื” ื”ื ื›ื ืกืช ื•ื”ื™ื•ืฆืืช. ื ืงื“ื™ืฉ ืชืฉื•ืžืช ืœื‘ ืžื™ื•ื—ื“ืช ืœื—ืกื™ืžืช ื”ืชืงืคื•ืช DDoS, ืคืขื™ืœื•ืช ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื•ื ื™ืกื™ื•ื ื•ืช ืœื ืฆืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืฉื™ืจื•ืชื™ื ื”ื ื’ื™ืฉื™ื ืžืจืฉืชื•ืช ืฆื™ื‘ื•ืจื™ื•ืช. ืœืฉื ื”ื‘ื”ื™ืจื•ืช, ื”ืชืงืคื•ืช ืžื”ืกื•ื’ื™ื ื”ื ืคื•ืฆื™ื ื‘ื™ื•ืชืจ ื™ื—ื•ืœื• ืกื™ืžื•ืœืฆื™ื”.

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 2: ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืจืืฉื•ื ื™ืช ืฉืœ Suricata

ื ื—ื™ืจื” ืื• ืกื•ืจื™ืงื˜ื”. ื—ืœืง 2: ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืจืืฉื•ื ื™ืช ืฉืœ Suricata

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”