 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Irregular Expressions &#187; suricata</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/Irregular-Expressions/tag/suricata/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions</link>
	<description>Insight into current security related events and exploits, including virtualization security and tips.</description>
	<lastBuildDate>Sun, 28 Apr 2013 08:00:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Professional IDS rules</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/professional-ids-rules/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/professional-ids-rules/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 03:10:11 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[ids rules]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[suricata]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/?p=419</guid>
		<description><![CDATA[Exciting news, there is a new professional feed available for your Suricata and Snort install. http://www.emergingthreatspro.com/ They are planning to support more platforms beyond Snort and Suricata, with full time research and daily updates. I can&#8217;t wait to see what other engines they are going to be supporting, I always like the idea of having another [...]]]></description>
				<content:encoded><![CDATA[<p>Exciting news, there is a new professional feed available for your Suricata and Snort install.</p>
<p>http://www.emergingthreatspro.com/</p>
<p>They are planning to support more platforms beyond Snort and Suricata, with full time research and daily updates.</p>
<p>I can&#8217;t wait to see what other engines they are going to be supporting, I always like the idea of having another feed in the environment. Nothing is %100 and its always best to spread out over as much as you can.</p>
<p>Now you can have a the new Suricata engine running the emerging threats rule set and your all set for taking on the latest and greatest coming out of the Open Information Security Foundation.</p>
<p>Enjoy!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/professional-ids-rules/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Suricata 1.0 release</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/suricata-10-release/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/suricata-10-release/#comments</comments>
		<pubDate>Fri, 02 Jul 2010 17:39:44 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[ids]]></category>
		<category><![CDATA[ids/ips]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[suricata]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/suricata-10-release/</guid>
		<description><![CDATA[The 1.0 release of the Suricata IPS/IDS has been released, you can get it here. http://www.openinfosecfoundation.org/index.php/download-suricata]]></description>
				<content:encoded><![CDATA[<p>The 1.0 release of the Suricata IPS/IDS has been released, you can get it here.</p>
<p>http://www.openinfosecfoundation.org/index.php/download-suricata</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/suricata-10-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Next generation IDS/IPS engine</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/next-generation-idsips-engine/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/next-generation-idsips-engine/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 13:24:59 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[ids]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[oisf]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[suricata]]></category>
		<category><![CDATA[vrt]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/?p=30</guid>
		<description><![CDATA[Suricata http://www.openinfosecfoundation.org I have been following this since there was first talk of creating a new engine.  They have released version 0.80. The engine is to load the current Snort rule sets and VRT rule sets out of the box! Once I complete my exam this week I will have some extra time and will [...]]]></description>
				<content:encoded><![CDATA[<p>Suricata</p>
<p>http://www.openinfosecfoundation.org</p>
<p>I have been following this since there was first talk of creating a new engine.  They have released version 0.80.</p>
<p>The engine is to load the current Snort rule sets and VRT rule sets out of the box!</p>
<p>Once I complete my exam this week I will have some extra time and will provide install instructions for FreeBSD.</p>
<p>The list of what they have added is extensive. (A the list to come is pretty long) There is more features on the way, listed in the official documentation.</p>
<p>Multi-Threading</p>
<p>Automatic Protocol Detection<br />
- IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB.</p>
<p>Gzip Decompression</p>
<p>Independent HTP Library<br />
- A total independant HTP libary that is also released under the GPLv2.</p>
<p>Standard Input Methods<br />
- You can use NFQueue, IPFRing, and the standard LibPcap to capture traffic.</p>
<p>Unified2 Output<br />
- You can use your standard output tools and methods with the new engine, 100% compatible!</p>
<p>Flow Variables<br />
- It’s possible to capture information out of a stream and save that in a variable which can then be matched again later.</p>
<p>Fast IP Matching<br />
- The engine will automatically take rules that are IP matches only (such as the RBN and compromised IP lists at Emerging Threats) and put them into a special fast matching preprocessor.</p>
<p>HTTP Log Module<br />
- All HTTP requests can be automatically output into an apache-style log format file. Very useful for monitoring and logging activity completely independent of rulesets and matching. Should you need to do so you could use the engine only as an HTTP logging sniffer.</p>
<p>(Source http://www.openinfosecfoundation.org/)</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/next-generation-idsips-engine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
