Suricata, the Terminator of IDS/IPS world
Éric Leblond
OISF
July 9, 2013
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 1 / 40
Suricata, the Terminator of IDS/IPS world ric Leblond OISF July 9, - - PowerPoint PPT Presentation
Suricata, the Terminator of IDS/IPS world ric Leblond OISF July 9, 2013 ric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 1 / 40 Some word about me Eric Leblond French Previously, co-founder and CTO of EdenWall
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 1 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 2 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 2 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 3 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 4 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 5 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 6 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 7 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 8 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 9 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 10 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 10 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 10 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 10 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 10 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 11 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 11 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 11 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 12 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 13 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 14 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 15 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 16 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 16 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 17 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 18 / 40
a l e r t http $HOME_NET any −> $EXTERNAL_NET $HTTP_PORTS \ ( msg: "ET CHAT Facebook Chat ( send message ) " ; \ flow : established , to_server ; content : "POST" ; http_method ; \ content : " / ajax / chat / send . php " ; h t t p _ u r i ; content : " facebook .com" ; http_header ; \ classtype : policy−v i o l a t i o n ; reference : url , doc . emergingthreats . net /2010784; \ reference : url ,www. emergingthreats . net / cgi−bin / cvsweb . cgi / sigs / POLICY / POLICY_Facebook_Chat ; \ sid :2010784; rev : 4 ; \ )
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 19 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 20 / 40
a l e r t http any any −> any any (msg: " windows exec " ; \ filemagic : " executable f o r MS Windows" ; sid : 1 ; rev : 1 ; )
a l e r t http any any −> any any (msg: " windows exec " ; filemagic : " executable f o r MS Windows" ; \ f i l e s t o r e ; sid : 1 ; rev : 1 ; )
a l e r t http any any −> any any (msg: " jpg claimed , but not jpg f i l e " ; \ f i l e e x t : " jpg " ; \ filemagic : ! "JPEG image data " ; sid : 1 ; rev : 1 ; )
a l e r t http any any −> any any (msg: " s e n s i t i v e f i l e leak " ; filename : " secret " ; sid : 1 ; rev : 1 ; ) Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 21 / 40
a l e r t http $EXTERNAL_NET −> $WEBSERVER any (msg: " suspicious upload " ; \ flow : established , to_server ; content : "POST" http_method ; \ content : " / upload . php " ; h t t p _ u r i ; \ filemagic : ! "PDF document " ; \ f i l e s t o r e ; sid : 1 ; rev : 1 ; )
a l e r t http $HOME_NET any −> $EXTERNAL_NET any (msg: " outgoing p ri v a t e key " ; \ filemagic : "RSA p ri v a t e key " ; sid : 1 ; rev : 1 ; ) Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 22 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 23 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 24 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 25 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 26 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 27 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 28 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 29 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 30 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 31 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 32 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 33 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 34 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 35 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 36 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 36 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 36 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 37 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 38 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 39 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 39 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 39 / 40
Éric Leblond (OISF) Suricata, the Terminator of IDS/IPS world July 9, 2013 40 / 40