SlideShare una empresa de Scribd logo
1 de 72
Descargar para leer sin conexión
Open Information Security Foundation

                 Suricata, The Next Generation IPS

                    Balancing Open Security Software
                                 with
                          Commercial Interests




Tuesday, August 3, 2010
Introduction


               EmergingThreats.net



                          Open Information Security Foundation
                                 OpenInfoSecFoundation.org




Tuesday, August 3, 2010
A Few Truths


                          Great Ideas Often Result
                          from Open Collaboration




Tuesday, August 3, 2010
A Few Truths


                          Open Source Projects Don’t
                          Become Effective Complete
                            Products on Their Own




Tuesday, August 3, 2010
A Few Truths


                          Open Community Hippies
                                Don’t Trust
                                 Vendors




Tuesday, August 3, 2010
A Few Truths


                                  Vendors
                           Don’t Collaborate With
                          Open Community Hippies
                                    Well




Tuesday, August 3, 2010
A Few Truths


                               The Military
                               Doesn’t Trust
                          Open Community Hippies




Tuesday, August 3, 2010
A Few Truths


                          Vendors try to Reinvent
                            the Wheel on Every
                             Military Contract




Tuesday, August 3, 2010
The Result


                           We have a


                    Hippie-Vendor-Mil Gap




Tuesday, August 3, 2010
Fixing it...




Tuesday, August 3, 2010
Fixing it...


                          (please don’t laugh)




Tuesday, August 3, 2010
Fixing it...


                          (please don’t laugh)




Tuesday, August 3, 2010
Fixing it...


                             (please don’t laugh)

                          We Involve The Government




Tuesday, August 3, 2010
Fixing it...


                             (please don’t laugh)

                          We Involve The Government




Tuesday, August 3, 2010
A Case Study




Tuesday, August 3, 2010
A Case Study


                          Intrusion Detection Systems




Tuesday, August 3, 2010
A Case Study


                          Intrusion Detection Systems
                                12+ Years Old




Tuesday, August 3, 2010
A Case Study


                          Intrusion Detection Systems
                                12+ Years Old
                             Open and Proprietary




Tuesday, August 3, 2010
A Case Study


                          Intrusion Detection Systems
                                12+ Years Old
                             Open and Proprietary
                              Productized by EV




Tuesday, August 3, 2010
A Case Study


                          In the last 5 years
                            No Innovation.
                                 Nada.
                                  Zilch.
                                 Nothing.




Tuesday, August 3, 2010
A Case Study




                          “IDS is Dead.”

                                           -Gartner



Tuesday, August 3, 2010
IDS


               • Intrusion Detection Has Not:
                          •   Innovated
                          •   Gone Multi-Threaded
                          •   Integrated with other technologies
                          •   Risen to solve our new threats




Tuesday, August 3, 2010
Tuesday, August 3, 2010
OISF




Tuesday, August 3, 2010
OISF


                          Non-Profit Foundation




Tuesday, August 3, 2010
OISF


                          Non-Profit Foundation
                           Initially DHS Funded




Tuesday, August 3, 2010
OISF


                             Non-Profit Foundation
                              Initially DHS Funded

                          OSH, Mil, and EV Involvement




Tuesday, August 3, 2010
The Dirty Little Secret




Tuesday, August 3, 2010
The Dirty Little Secret


                             It’s working!




Tuesday, August 3, 2010
The Dirty Little Secret


                             It’s working!
                                  Why?




Tuesday, August 3, 2010
The Dirty Little Secret




Tuesday, August 3, 2010
The Dirty Little Secret


          The OSH, EV, Consumers, Mil, and Government




Tuesday, August 3, 2010
The Dirty Little Secret


          The OSH, EV, Consumers, Mil, and Government


             ALL WANT THE SAME THING




Tuesday, August 3, 2010
The Dirty Little Secret


                                   New Ideas
                              Constant Innovation
                            Reliable Implementations
                                Effective Support
                          Put their Kids through College




Tuesday, August 3, 2010
Consortium




Tuesday, August 3, 2010
Consortium



                          Vendors are part of a Consortium




Tuesday, August 3, 2010
Consortium



                   Vendors are part of a Consortium
                50/50 voting rights with the Community




Tuesday, August 3, 2010
Consortium



                   Vendors are part of a Consortium
                50/50 voting rights with the Community
                 Support required for a non-GPL license




Tuesday, August 3, 2010
OISF Consortium




Tuesday, August 3, 2010
Consortium


             •Currently Bringing in 19 New Members
                   •Global Defense Contractors...
                   •Several Government Research Groups
                   •Many CERTs
                   •Universities
                   •Security Vendors (that use other engines...)




Tuesday, August 3, 2010
The Engine




Tuesday, August 3, 2010
Features



                          Major Goals




Tuesday, August 3, 2010
Features



                          Multi-Threading




Tuesday, August 3, 2010
Features



                          Native IPv6 Support




Tuesday, August 3, 2010
Features



                          Snort Syntax

                          with additions




Tuesday, August 3, 2010
Features



                 Automatic Protocol Detection




Tuesday, August 3, 2010
Features



                          High Speed Regex




Tuesday, August 3, 2010
Features



                          Advanced HTTP Parsing




Tuesday, August 3, 2010
Features



                          Multiple Model
                 Statistical Anomaly Detection




Tuesday, August 3, 2010
Features



                Native Hardware Acceleration
                           Support




Tuesday, August 3, 2010
Features




                          GPU Acceleration




Tuesday, August 3, 2010
Features



                          IP Reputation

        Distributed Blocking and Feedback




Tuesday, August 3, 2010
Features




                          Scoring Thresholds




Tuesday, August 3, 2010
Features




                          Very High Speed Regex




Tuesday, August 3, 2010
Features




                          In Stream File Extraction




Tuesday, August 3, 2010
Features




                   Web-Based Config Manager




Tuesday, August 3, 2010
Other Features


                      HTTP Access Logging
                      SMB Access/Action Logging
                      Windows INLINE Support
                      Full Windows Support
                      Virtual Environment Support
                      Stopbadware.org URI Matching
                      Passive SSL Decryption


Tuesday, August 3, 2010
Features



                          Go ask your Commercial
                           Vendor for any of that....




Tuesday, August 3, 2010
Status


          Releases
                 •Initial Stable Release, December 31, 2010
                 •Second Stable Release, February 15, 2010
                 •Phase One RC1, May 6, 2010
                 •Phase One Production, July 1, 2010




Tuesday, August 3, 2010
Get Involved


                          Brainstorming Meeting
                               July 16, 2010
                               San Francisco




Tuesday, August 3, 2010
Get Involved
                          Interim Goals:
                          Architecture Documentation
                          Performance Optimization
                          Run Mode Support (Likely Endace completed)
                          Error Code Cleanup and Documentation
                          Full Documentation (community interactable docs)
                          Advanced Profiling and Engine stats
                          Accuracy Improvements
                          Add Protocol Detections (SMTP, etc)
                          Classifications Update
                          2.8.6 Compatibility
                          LibHTP Error Handling
                          Heavy Inline Testing




Tuesday, August 3, 2010
Get Involved


                          Phase Two:
                          Max Inspection Time
                          File Capture in Stream
                          REGEX Optimization/Accel
                          Live Ruleset Updates
                          Flow Logging (Netflow)
                          Add Replace keyword support
                          Host attribute scrubbing
                          URI Matching lookups (stopbadware, websense, etc)
                          CUDA Support




Tuesday, August 3, 2010
Get Involved


                          Phase Two Team Two:
                          IP Reputation - Explore other items, dns, etc
                          Distributed Blocking
                          Global Flowbits and flowvars
                          Full Stream Capture
                          Traffic Redirection




Tuesday, August 3, 2010
What We Need




Tuesday, August 3, 2010
What We Need

                          Consortium Members




Tuesday, August 3, 2010
What We Need

                          Consortium Members
                            Coding Support




Tuesday, August 3, 2010
What We Need

                               Consortium Members
                                 Coding Support

                          Further Government/Mil Support




Tuesday, August 3, 2010
What We Need

                               Consortium Members
                                 Coding Support

                          Further Government/Mil Support


                                     YOU!



Tuesday, August 3, 2010
Tuesday, August 3, 2010
Will you get involved?




Tuesday, August 3, 2010
Will you get involved?

                               Questions?




Tuesday, August 3, 2010
www.EmergingThreats.net




Tuesday, August 3, 2010

Más contenido relacionado

Similar a The Next Generation Open IDS Engine Suricata and Emerging Threats

Similar a The Next Generation Open IDS Engine Suricata and Emerging Threats (8)

Linked Data Publishing Three-Step
Linked Data Publishing Three-StepLinked Data Publishing Three-Step
Linked Data Publishing Three-Step
 
Our Approach in Design
Our Approach in DesignOur Approach in Design
Our Approach in Design
 
Building a Digital Gameplan for Events
Building a Digital Gameplan for EventsBuilding a Digital Gameplan for Events
Building a Digital Gameplan for Events
 
From Creative to Planning
From Creative to PlanningFrom Creative to Planning
From Creative to Planning
 
Re/wiring Brains · Andres Colmenares
Re/wiring Brains · Andres ColmenaresRe/wiring Brains · Andres Colmenares
Re/wiring Brains · Andres Colmenares
 
Interact - How to create an App?
Interact - How to create an App?Interact - How to create an App?
Interact - How to create an App?
 
Devops culturelt
Devops cultureltDevops culturelt
Devops culturelt
 
Ethical Leadership
Ethical LeadershipEthical Leadership
Ethical Leadership
 

Más de Joshua L. Davis

Innovation Through “Trusted” Open Source Solutions
Innovation Through “Trusted” Open Source SolutionsInnovation Through “Trusted” Open Source Solutions
Innovation Through “Trusted” Open Source SolutionsJoshua L. Davis
 
The Open Source Movement
The Open Source MovementThe Open Source Movement
The Open Source MovementJoshua L. Davis
 
Mil-OSS @ 47th Annual AOC Convention
Mil-OSS @ 47th Annual AOC ConventionMil-OSS @ 47th Annual AOC Convention
Mil-OSS @ 47th Annual AOC ConventionJoshua L. Davis
 
DISA's Open Source Corporate Management Information System (OSCMIS)
DISA's Open Source Corporate Management Information System (OSCMIS)DISA's Open Source Corporate Management Information System (OSCMIS)
DISA's Open Source Corporate Management Information System (OSCMIS)Joshua L. Davis
 
Ignite: Hackin' Excel with Ruby
Ignite: Hackin' Excel with RubyIgnite: Hackin' Excel with Ruby
Ignite: Hackin' Excel with RubyJoshua L. Davis
 
Ignite: Improving Performance on Federal Contracts Using Scrum & Agile
Ignite: Improving Performance on Federal Contracts Using Scrum & AgileIgnite: Improving Performance on Federal Contracts Using Scrum & Agile
Ignite: Improving Performance on Federal Contracts Using Scrum & AgileJoshua L. Davis
 
Using the Joomla CMI in the Army Hosting Environment
Using the Joomla CMI in the Army Hosting EnvironmentUsing the Joomla CMI in the Army Hosting Environment
Using the Joomla CMI in the Army Hosting EnvironmentJoshua L. Davis
 
Senior Leaders Adapting to Social Technologies
Senior Leaders Adapting to Social TechnologiesSenior Leaders Adapting to Social Technologies
Senior Leaders Adapting to Social TechnologiesJoshua L. Davis
 
Barcamp: Open Source and Security
Barcamp: Open Source and SecurityBarcamp: Open Source and Security
Barcamp: Open Source and SecurityJoshua L. Davis
 
Open Source Software (OSS/FLOSS) and Security
Open Source Software (OSS/FLOSS) and SecurityOpen Source Software (OSS/FLOSS) and Security
Open Source Software (OSS/FLOSS) and SecurityJoshua L. Davis
 
Importance of WS-Addressing and WS-Reliability in DoD Enterprises
Importance of WS-Addressing and WS-Reliability in DoD EnterprisesImportance of WS-Addressing and WS-Reliability in DoD Enterprises
Importance of WS-Addressing and WS-Reliability in DoD EnterprisesJoshua L. Davis
 
OZONE & OWF: A Community-wide GOTS initiative and its transition to GOSS
OZONE & OWF: A Community-wide GOTS initiative and its transition to GOSSOZONE & OWF: A Community-wide GOTS initiative and its transition to GOSS
OZONE & OWF: A Community-wide GOTS initiative and its transition to GOSSJoshua L. Davis
 
Title TBD: "18 hundred seconds"
Title TBD: "18 hundred seconds"Title TBD: "18 hundred seconds"
Title TBD: "18 hundred seconds"Joshua L. Davis
 
Reaching It's Potential: How to Make Government-Developed OSS A Major Player
Reaching It's Potential: How to Make Government-Developed OSS A Major PlayerReaching It's Potential: How to Make Government-Developed OSS A Major Player
Reaching It's Potential: How to Make Government-Developed OSS A Major PlayerJoshua L. Davis
 
Homeland Open Security Technologies (HOST)
Homeland Open Security Technologies (HOST)Homeland Open Security Technologies (HOST)
Homeland Open Security Technologies (HOST)Joshua L. Davis
 
USIP Open Simulation Platform
USIP Open Simulation PlatformUSIP Open Simulation Platform
USIP Open Simulation PlatformJoshua L. Davis
 
OSSIM and OMAR in the DoD/IC
OSSIM and OMAR in the DoD/ICOSSIM and OMAR in the DoD/IC
OSSIM and OMAR in the DoD/ICJoshua L. Davis
 

Más de Joshua L. Davis (20)

Innovation Through “Trusted” Open Source Solutions
Innovation Through “Trusted” Open Source SolutionsInnovation Through “Trusted” Open Source Solutions
Innovation Through “Trusted” Open Source Solutions
 
The Open Source Movement
The Open Source MovementThe Open Source Movement
The Open Source Movement
 
Mil-OSS @ 47th Annual AOC Convention
Mil-OSS @ 47th Annual AOC ConventionMil-OSS @ 47th Annual AOC Convention
Mil-OSS @ 47th Annual AOC Convention
 
DISA's Open Source Corporate Management Information System (OSCMIS)
DISA's Open Source Corporate Management Information System (OSCMIS)DISA's Open Source Corporate Management Information System (OSCMIS)
DISA's Open Source Corporate Management Information System (OSCMIS)
 
Ignite: Hackin' Excel with Ruby
Ignite: Hackin' Excel with RubyIgnite: Hackin' Excel with Ruby
Ignite: Hackin' Excel with Ruby
 
Ignite: YSANAOYOA
Ignite: YSANAOYOAIgnite: YSANAOYOA
Ignite: YSANAOYOA
 
Ignite: Improving Performance on Federal Contracts Using Scrum & Agile
Ignite: Improving Performance on Federal Contracts Using Scrum & AgileIgnite: Improving Performance on Federal Contracts Using Scrum & Agile
Ignite: Improving Performance on Federal Contracts Using Scrum & Agile
 
Using the Joomla CMI in the Army Hosting Environment
Using the Joomla CMI in the Army Hosting EnvironmentUsing the Joomla CMI in the Army Hosting Environment
Using the Joomla CMI in the Army Hosting Environment
 
Senior Leaders Adapting to Social Technologies
Senior Leaders Adapting to Social TechnologiesSenior Leaders Adapting to Social Technologies
Senior Leaders Adapting to Social Technologies
 
Barcamp: Open Source and Security
Barcamp: Open Source and SecurityBarcamp: Open Source and Security
Barcamp: Open Source and Security
 
Open Source Software (OSS/FLOSS) and Security
Open Source Software (OSS/FLOSS) and SecurityOpen Source Software (OSS/FLOSS) and Security
Open Source Software (OSS/FLOSS) and Security
 
SOSCOE Overview
SOSCOE OverviewSOSCOE Overview
SOSCOE Overview
 
milSuite
milSuitemilSuite
milSuite
 
Importance of WS-Addressing and WS-Reliability in DoD Enterprises
Importance of WS-Addressing and WS-Reliability in DoD EnterprisesImportance of WS-Addressing and WS-Reliability in DoD Enterprises
Importance of WS-Addressing and WS-Reliability in DoD Enterprises
 
OZONE & OWF: A Community-wide GOTS initiative and its transition to GOSS
OZONE & OWF: A Community-wide GOTS initiative and its transition to GOSSOZONE & OWF: A Community-wide GOTS initiative and its transition to GOSS
OZONE & OWF: A Community-wide GOTS initiative and its transition to GOSS
 
Title TBD: "18 hundred seconds"
Title TBD: "18 hundred seconds"Title TBD: "18 hundred seconds"
Title TBD: "18 hundred seconds"
 
Reaching It's Potential: How to Make Government-Developed OSS A Major Player
Reaching It's Potential: How to Make Government-Developed OSS A Major PlayerReaching It's Potential: How to Make Government-Developed OSS A Major Player
Reaching It's Potential: How to Make Government-Developed OSS A Major Player
 
Homeland Open Security Technologies (HOST)
Homeland Open Security Technologies (HOST)Homeland Open Security Technologies (HOST)
Homeland Open Security Technologies (HOST)
 
USIP Open Simulation Platform
USIP Open Simulation PlatformUSIP Open Simulation Platform
USIP Open Simulation Platform
 
OSSIM and OMAR in the DoD/IC
OSSIM and OMAR in the DoD/ICOSSIM and OMAR in the DoD/IC
OSSIM and OMAR in the DoD/IC
 

Último

Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DaySri Ambati
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 

Último (20)

Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 

The Next Generation Open IDS Engine Suricata and Emerging Threats

  • 1. Open Information Security Foundation Suricata, The Next Generation IPS Balancing Open Security Software with Commercial Interests Tuesday, August 3, 2010
  • 2. Introduction EmergingThreats.net Open Information Security Foundation OpenInfoSecFoundation.org Tuesday, August 3, 2010
  • 3. A Few Truths Great Ideas Often Result from Open Collaboration Tuesday, August 3, 2010
  • 4. A Few Truths Open Source Projects Don’t Become Effective Complete Products on Their Own Tuesday, August 3, 2010
  • 5. A Few Truths Open Community Hippies Don’t Trust Vendors Tuesday, August 3, 2010
  • 6. A Few Truths Vendors Don’t Collaborate With Open Community Hippies Well Tuesday, August 3, 2010
  • 7. A Few Truths The Military Doesn’t Trust Open Community Hippies Tuesday, August 3, 2010
  • 8. A Few Truths Vendors try to Reinvent the Wheel on Every Military Contract Tuesday, August 3, 2010
  • 9. The Result We have a Hippie-Vendor-Mil Gap Tuesday, August 3, 2010
  • 11. Fixing it... (please don’t laugh) Tuesday, August 3, 2010
  • 12. Fixing it... (please don’t laugh) Tuesday, August 3, 2010
  • 13. Fixing it... (please don’t laugh) We Involve The Government Tuesday, August 3, 2010
  • 14. Fixing it... (please don’t laugh) We Involve The Government Tuesday, August 3, 2010
  • 15. A Case Study Tuesday, August 3, 2010
  • 16. A Case Study Intrusion Detection Systems Tuesday, August 3, 2010
  • 17. A Case Study Intrusion Detection Systems 12+ Years Old Tuesday, August 3, 2010
  • 18. A Case Study Intrusion Detection Systems 12+ Years Old Open and Proprietary Tuesday, August 3, 2010
  • 19. A Case Study Intrusion Detection Systems 12+ Years Old Open and Proprietary Productized by EV Tuesday, August 3, 2010
  • 20. A Case Study In the last 5 years No Innovation. Nada. Zilch. Nothing. Tuesday, August 3, 2010
  • 21. A Case Study “IDS is Dead.” -Gartner Tuesday, August 3, 2010
  • 22. IDS • Intrusion Detection Has Not: • Innovated • Gone Multi-Threaded • Integrated with other technologies • Risen to solve our new threats Tuesday, August 3, 2010
  • 25. OISF Non-Profit Foundation Tuesday, August 3, 2010
  • 26. OISF Non-Profit Foundation Initially DHS Funded Tuesday, August 3, 2010
  • 27. OISF Non-Profit Foundation Initially DHS Funded OSH, Mil, and EV Involvement Tuesday, August 3, 2010
  • 28. The Dirty Little Secret Tuesday, August 3, 2010
  • 29. The Dirty Little Secret It’s working! Tuesday, August 3, 2010
  • 30. The Dirty Little Secret It’s working! Why? Tuesday, August 3, 2010
  • 31. The Dirty Little Secret Tuesday, August 3, 2010
  • 32. The Dirty Little Secret The OSH, EV, Consumers, Mil, and Government Tuesday, August 3, 2010
  • 33. The Dirty Little Secret The OSH, EV, Consumers, Mil, and Government ALL WANT THE SAME THING Tuesday, August 3, 2010
  • 34. The Dirty Little Secret New Ideas Constant Innovation Reliable Implementations Effective Support Put their Kids through College Tuesday, August 3, 2010
  • 36. Consortium Vendors are part of a Consortium Tuesday, August 3, 2010
  • 37. Consortium Vendors are part of a Consortium 50/50 voting rights with the Community Tuesday, August 3, 2010
  • 38. Consortium Vendors are part of a Consortium 50/50 voting rights with the Community Support required for a non-GPL license Tuesday, August 3, 2010
  • 40. Consortium •Currently Bringing in 19 New Members •Global Defense Contractors... •Several Government Research Groups •Many CERTs •Universities •Security Vendors (that use other engines...) Tuesday, August 3, 2010
  • 42. Features Major Goals Tuesday, August 3, 2010
  • 43. Features Multi-Threading Tuesday, August 3, 2010
  • 44. Features Native IPv6 Support Tuesday, August 3, 2010
  • 45. Features Snort Syntax with additions Tuesday, August 3, 2010
  • 46. Features Automatic Protocol Detection Tuesday, August 3, 2010
  • 47. Features High Speed Regex Tuesday, August 3, 2010
  • 48. Features Advanced HTTP Parsing Tuesday, August 3, 2010
  • 49. Features Multiple Model Statistical Anomaly Detection Tuesday, August 3, 2010
  • 50. Features Native Hardware Acceleration Support Tuesday, August 3, 2010
  • 51. Features GPU Acceleration Tuesday, August 3, 2010
  • 52. Features IP Reputation Distributed Blocking and Feedback Tuesday, August 3, 2010
  • 53. Features Scoring Thresholds Tuesday, August 3, 2010
  • 54. Features Very High Speed Regex Tuesday, August 3, 2010
  • 55. Features In Stream File Extraction Tuesday, August 3, 2010
  • 56. Features Web-Based Config Manager Tuesday, August 3, 2010
  • 57. Other Features HTTP Access Logging SMB Access/Action Logging Windows INLINE Support Full Windows Support Virtual Environment Support Stopbadware.org URI Matching Passive SSL Decryption Tuesday, August 3, 2010
  • 58. Features Go ask your Commercial Vendor for any of that.... Tuesday, August 3, 2010
  • 59. Status  Releases •Initial Stable Release, December 31, 2010 •Second Stable Release, February 15, 2010 •Phase One RC1, May 6, 2010 •Phase One Production, July 1, 2010 Tuesday, August 3, 2010
  • 60. Get Involved Brainstorming Meeting July 16, 2010 San Francisco Tuesday, August 3, 2010
  • 61. Get Involved Interim Goals: Architecture Documentation Performance Optimization Run Mode Support (Likely Endace completed) Error Code Cleanup and Documentation Full Documentation (community interactable docs) Advanced Profiling and Engine stats Accuracy Improvements Add Protocol Detections (SMTP, etc) Classifications Update 2.8.6 Compatibility LibHTP Error Handling Heavy Inline Testing Tuesday, August 3, 2010
  • 62. Get Involved Phase Two: Max Inspection Time File Capture in Stream REGEX Optimization/Accel Live Ruleset Updates Flow Logging (Netflow) Add Replace keyword support Host attribute scrubbing URI Matching lookups (stopbadware, websense, etc) CUDA Support Tuesday, August 3, 2010
  • 63. Get Involved Phase Two Team Two: IP Reputation - Explore other items, dns, etc Distributed Blocking Global Flowbits and flowvars Full Stream Capture Traffic Redirection Tuesday, August 3, 2010
  • 64. What We Need Tuesday, August 3, 2010
  • 65. What We Need Consortium Members Tuesday, August 3, 2010
  • 66. What We Need Consortium Members Coding Support Tuesday, August 3, 2010
  • 67. What We Need Consortium Members Coding Support Further Government/Mil Support Tuesday, August 3, 2010
  • 68. What We Need Consortium Members Coding Support Further Government/Mil Support YOU! Tuesday, August 3, 2010
  • 70. Will you get involved? Tuesday, August 3, 2010
  • 71. Will you get involved? Questions? Tuesday, August 3, 2010