Versie 2.0 van Suricata is uitgekomen. Suricata is een opensource network intrusion detection system (IDS), intrusion prevention system (IPS) en network security monitoring engine. Het kan worden gebruikt om netwerkverkeer te monitoren en een systeembeheerder een waarschuwing te geven als er iets verdachts wordt gesignaleerd. De ontwikkeling wordt overzien door de Open Information Security Foundation, met hulp van de community en diverse fabrikanten. De belangrijkste verandering in versie 2.0 is Eve, een volledig op json gebaseerd logsysteem. Eve kan onder meer met Logstash worden gebruikt om zo informatie grafisch weer te geven. De complete changelog voor versie 2.0 is hieronder te vinden.
Notable new features, improvements and changes
- Eve log, all JSON event output for alerts, HTTP, DNS, SSH, TLS and files. Written by Tom Decanio of nPulse Technologies
- NSM runmode, where detection engine is disabled. Development supported by nPulse Technologies
- Various scalability improvements, clean ups and fixes by Ken Steel of Tilera
- Add –set commandline option to override any YAML option, by Jason Ish of Emulex
- Several fixes and improvements of AF_PACKET and PF_RING
- ICMPv6 handling improvements by Jason Ish of Emulex
- Alerting over PCIe bus (Tilera only), by Ken Steel of Tilera
- Feature #792: DNS parser, logger and keyword support, funded by Emerging Threats
- Feature #234: add option disable/enable individual app layer protocol inspection modules
- Feature #417: ip fragmentation time out feature in yaml
- Feature #1009: Yaml file inclusion support
- Feature #478: XFF (X-Forwarded-For) support in Unified2
- Feature #602: availability for http.log output – identical to apache log format
- Feature #813: VLAN flow support
- Feature #901: VLAN defrag support
- Features #814, #953, #1102: QinQ VLAN handling
- Feature #751: Add invalid packet counter
- Feature #944: detect nic offloading
- Feature #956: Implement IPv6 reject
- Feature #775: libhtp 0.5.x support
- Feature #470: Deflate support for HTTP response bodies
- Feature #593: Lua flow vars and flow ints support
- Feature #983: Provide rule support for specifying icmpv4 and icmpv6
- Feature #1008: Optionally have http_uri buffer start with uri path for use in proxied environments
- Feature #1032: profiling: per keyword stats
- Feature #878: add storage api
Logstash Kibana gevoed met informatie van Suricata met json-output.