prelude-correlator/master: Update NEWS, bump version.

[email protected] Mon, 2 Nov 2009 11:00:59 +0100 (CET)
Newsgroups gmane.comp.security.ids.prelude.cvs
Message-ID <[email protected]>
commit d3c6c5aae5ddd818789afeab57610b581ca75907
Author: Yoann Vandoorselaere <[email protected]>
Date:   Mon Nov 2 11:00:08 2009 +0100

    Update NEWS, bump version.


========================================

 NEWS |   26 ++++++++++++++++++++++++++
 1 files changed, 26 insertions(+), 0 deletions(-)

========================================

diff --git a/NEWS b/NEWS
index 0261d74..a405aee 100644
--- a/NEWS
+++ b/NEWS
@@ -1,3 +1,29 @@
+* 2009-11-02, prelude-correlator-0.9.0-beta7:
+
+- Initial SpamhausDrop plugin implementation, by
+  Wes Young <[email protected]> (closes #363)
+
+- Do not discard --root parameters if prefix is absolute.
+
+- Python 2.4 backward compatibility fixes.
+
+- Handle plugin loading error gracefully.
+
+- Improve WormPlugin accuracy, and make it carry a reference to the
+  initial event. The plugin used to alert when seeing an alert to a
+  given target, and this same alert going back to the source. This can
+  happen in a number of case (example: Netbios alert triggered by Snort)
+
+  As of now, the plugin will wait for the events to be repeated against
+  at least 5 differents hosts.
+
+- Dshield CorrelationAlert now handle multiples events. Previously, we
+  used to generate a single Dshield CorrelationAlert for each events
+  where the source address would match the Dshield database. The plugin
+  now generate CorrelationAlert for multiples events received from the
+  same source.
+
+
 * 2009-07-09, prelude-correlator-0.9.0-beta6:
 
 - Provide a default configuration file, and fixes the prelude-correlator
_______________________________________________
Prelude-cvslog site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-cvslog