Software update: Suricata 3.1

Spread the love

The first major release since version 3.0 of Suricata has been released and carries version number 3.1. Suricata is an open source network intrusion detection system (IDS), intrusion prevention system (IPS), and network security monitoring engine. It can be used to monitor network traffic and alert a system administrator if anything suspicious is detected. Development is overseen by the Open Information Security Foundation, with support from the community and various manufacturers. The with it on json Based logging system Eve collected data can be done with, among other things, log stash are used to display information graphically again at to give. The release notes for version 3.1 can be found below.

Suricata 3.1 released!

We’re proud to announce Suricata 3.1.

This release brings significant improvements on the performance side:

  • Hyperscan integration for Multi Pattern Matcher and Single Pattern Matcher. If installed, Hyperscan is now the default.
  • Rewrite of the detection engine, simplifying rule grouping. This improves performance, while reducing memory usage and start up time in many scenarios.

Packet capture got a lot of attention:

  • AF_PACKET support for tpacket-v3 (experimental)
  • NETMAP usability improvements, especially on FreeBSD

config:

  • Reorganized default configuration layout provides for intuitive and easy set up.

This release also comes with libhtp 0.5.20, in which we address a number of issues Steffen Ullrich of HTTP Evader reported.

A new keyword ‘tls_sni’ was added, including MPM support. It allows matching on the TLS SNI field.

Other than that, lots of clean ups and optimizations:

  • locking has been much simplified
  • TCP and IPv6 decoder optimizations
  • unit test clean ups
  • AFL fuzz testing options were added

Have a look at the full change log

Logstash Kibana fed with information from Suricata with json output.

Version number 3.1
Release status Final
Operating systems Windows 7, Linux, BSD, macOS, UNIX, Windows Vista, Windows 8, Windows 10
Website Suricata
Download
License type GPL
You might also like