Suricata ( https://suricata.io/ ) is an open-source Threat Detection Engine owned and maintained by Open Information Security Foundation (OISF) ( https://oisf.net/ ). It works as an IDS and as well as an IPS to help cybersecurity analysts detect and protect against malicious network activities. Signature based rulesets play an important role in identifying and detecting malicious threats in a live network. Emerging Threats Open Ruleset ( https://rules.emergingthreats.net/ ) for Suricata detection engine can be found in /etc./suricata/rules directory of the Suricata distribution. These open rulesets for Suricata distribution are often referred as Suricata Rules. The open version of Suricata Rules consist of more than 36,000 rule signatures. These 36,000 signatures are not only just part of Suricata engine, but also are in active use in many other detection engines. In this paper, we will expose many interesting artifacts about Suricata Rules through frequency analysis. The insights gained from our analysis can be exploited to have a performance-optimized implementation of a threat detection engine using an open version of Suricata rules.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Why is Statistical Analysis of Suricata Rules Important?

  • Debapriyay Mukhopadhyay,
  • Sobhan Patra,
  • Naveen Jaiswal

摘要

Suricata ( https://suricata.io/ ) is an open-source Threat Detection Engine owned and maintained by Open Information Security Foundation (OISF) ( https://oisf.net/ ). It works as an IDS and as well as an IPS to help cybersecurity analysts detect and protect against malicious network activities. Signature based rulesets play an important role in identifying and detecting malicious threats in a live network. Emerging Threats Open Ruleset ( https://rules.emergingthreats.net/ ) for Suricata detection engine can be found in /etc./suricata/rules directory of the Suricata distribution. These open rulesets for Suricata distribution are often referred as Suricata Rules. The open version of Suricata Rules consist of more than 36,000 rule signatures. These 36,000 signatures are not only just part of Suricata engine, but also are in active use in many other detection engines. In this paper, we will expose many interesting artifacts about Suricata Rules through frequency analysis. The insights gained from our analysis can be exploited to have a performance-optimized implementation of a threat detection engine using an open version of Suricata rules.