Forums

Resolved
0 votes
Hi

I want to know if anyone has had a look at / has any experience with Suricata IDS (http://suricata-ids.org/ ; http://suricata-ids.org/features/all-features/ )? What do the ClearOS devs think about it compared to Snort? Would it be difficult to change ClearOS over from Snort to Suricata?

Regards
Wednesday, December 10 2014, 06:42 AM
Share this post:
Responses (4)
  • Accepted Answer

    Saturday, January 10 2015, 06:50 AM - #Permalink
    Resolved
    0 votes
    Hi guys

    Looks like Cisco are working on Snort 3 (https://www.snort.org/snort3). It looks like it will have features similar to Suricata. It's in alpha at the moment.

    I also see that the latest version of Snot (v 2.9.7) has OpenAppID built in that can do application identification - see the release notes: https://www.snort.org/downloads/snort/release_notes_2.9.7.0.txt
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, December 24 2014, 01:12 PM - #Permalink
    Resolved
    0 votes
    HI Nick

    From what I've read about Suricata vs Snort, is that Suricata is multi-thread cable and it also uses a L7-filter type of protocol detection (One advantage Suricata has is its ability to understand level 7 of the OSI model, which enhances its ability of detecting malwares. Suricata has demonstrated that it is far more efficient than Snort for detecting malwares, viruses and shellcodes). What is also nice is that Suricata can use Snort and ET rules.

    It sounds quite interesting and would like to know what the dev's think of it.

    Have a look at: http://www.aldeid.com/wiki/Suricata-vs-snort
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, December 24 2014, 12:44 PM - #Permalink
    Resolved
    0 votes
    It has been thought about but did not make the wish list. Any reason for wanting it? I read a comparison a while back and there seem to be pros and cons.
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, December 24 2014, 11:30 AM - #Permalink
    Resolved
    0 votes
    Anyone?
    The reply is currently minimized Show
Your Reply