[ANNOUNCE]: Prelude-Correlator 1.0.0 Release Candidate 1
Yoann Vandoorselaere <[email protected]> Fri, 29 Jan 2010 18:40:32 +0100
| Newsgroups | gmane.comp.security.ids.prelude.user,gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1264786832.27716.3034.camel@arwen> |
We are pleased to announce the availability of Prelude-Correlator 1.0.0rc1 ! With this first release candidate, we hope to collect comments and bug reports from the Prelude community in order to solve the remaining problems with the current Prelude codebase to ensure a final 1.0 release that is rock solid! We would like to encourage anyone who is willing and able to spend some time on testing to find and report problems to the Prelude developers. The final 1.0.0 release is expected to be released in February. Prelude-Correlator serves to correlate, in real time, the multiple events received by Prelude. Several isolated alerts, generated from different probes, can thus trigger a single correlation alert should the events be related. ------[ CHANGES ]------ - [Firewall]: The plugin will now report CorrelationAlert for events / sets of events that appear to have passed through a firewall known to protect the target machine. If no firewall ever emit block concerning a given host, then this host is considered un-protected, and there is no point in reporting CorrelationAlert. - [OpenSSHAuth]: The plugin has been modified so that it can now generate a single CorrelationAlert for multiples authentication method used in a given time slice. - [Spamhaus]: The plugin has been modified so that it can now generate a single CorrelationAlert for multiples events received from the same source. - [BruteForce]: Various improvement, do not limit the number of events the plugin is able to report in a single CorrelationAlert. - [Scan]: do not limit the number of events the plugin is able to report in a single CorrelationAlert. - Context initialization now take an optional 'overwrite' argument. This argument, if set to False, mean that the Context() will be returned un-modified if it already exist. If it doesn't, it will be created. - New Context.update() method, which provide exactly the same functionality as calling Context() with the 'update=True' argument. This is useful since some plugin need to defer an update to another place in the code. - If the context creation/update function is called with an IDMEF message parameter, then we automatically call addAlertReference on the context CorrelationAlert using the provided message as the parameter. - Make it possible to change context option on update - Automatically set CorrelationAlert DetectTime : reported CorrelationAlert DetectTime now match the time of the first event that was detected. - Make it possible for plugin to specify a function to be called on Timer expiration. - Disable BusinessHour correlation by default since it is very verbose - Various bug fixes. ------[ SUPPORT ] ------ Improving Prelude is costly, but you can help! We are looking for organizations that find Prelude useful and wish to contribute back. Commercial support contracts for Prelude are available, and they help finance continued maintenance. PreludeIDS Technologies, a privately held company, is currently funding Prelude maintenance. ------[ DOWNLOAD ]------ http://www.prelude-ids.com/development/download/ ------[ CHECKSUM ]------ MD5 : 8315d7401905e5058e2b3b7c37f7e46e SHA1 : e468dd13447fe52a0f1e562849f89854bc9599dc SHA256 : e5d3fc5a379eecc35a280635619e9747e4e8f59c4e2c90d685d60033565bcbf5 ------[ OpenPGP key ]------ gpg --keyserver wwwkeys.pgp.net --recv-keys 0x23D2FAC3 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAABAgAGBQJLYxROAAoJEBHxO34j0vrDXFgP/0ku2Xzaqabvk9QdbykPvruO HxkN8vc33/GeNBOsSL1LQZhBZngqWLYZeuy4UaLVAvzY5VPtlg/TIyHJcg8DU4VF nYQH7m48Dbf+zDsR5RgypiTruCrzVmOKQ0pEyy6g7ZZxR07yZAL5Y0BndEe3vYMb JVtRuOef7TeCc+oehRrZJJCPVopYS7iPpMRLNP/9AwrO8IBJGUyeRGk1BJUxnkri guel9cjZW5Yg9j95ybBoDjBs7y8+VyiDYSPZuJpFuuRC+9wDBsAMX5lavjNzmcE6 +CBekDIQiS4uqUb/2e1rrQLadVCEdPmeQDYvj0+ixVPgvJ/bYXoLtFuf6eLvaHsy HgW6WpBaLNhQTGqoe6m/ppMQ/OQQy/M3dkXG9G8cwixDTYXq2EPfblByjy3JVobx VxlOxncSNuKCiRVQWH6G7MiFzVmYmsI+4VUIHKc+Pzje6uIRu4gLDcF0K6U/lOk/ G5wIMBcy+6hCHbfP+L2Y3cr7WGVgb0OQMojFClnTr6lOO3sJnrhpV6Dzd+OYFnPP zXfrJVH0zKEqHy6PVzK1yb3oDYGaANO268/kwGPPGKpgGpDLNkGdDSjnWiEj58se +SlKmQtzIE/Zy3HNoAxk6PHaiC5PrLZYBRz2dMJ8C2yFhapAr/8MJa/cNv/7H/pB 6kX+llenYaEEoBSnQX1z =3CVx -----END PGP SIGNATURE----- -- Yoann Vandoorselaere | Directeur Technique/CTO | PreludeIDS Technologies Tel: +33 (0)1 40 24 65 10 Fax: +33 (0)1 40 24 65 28 http://www.prelude-ids.com _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user