[ANNOUNCE]: Prelude-Correlator 1.0.0 Release Candidate 1

Yoann Vandoorselaere <[email protected]> Fri, 29 Jan 2010 18:40:32 +0100
Newsgroups gmane.comp.security.ids.prelude.user,gmane.comp.security.ids.prelude.devel
Message-ID <1264786832.27716.3034.camel@arwen>
We are pleased to announce the availability of Prelude-Correlator
1.0.0rc1 ! 

With this first release candidate, we hope to collect comments and bug
reports from the Prelude community in order to solve the remaining
problems with the current Prelude codebase to ensure a final 1.0 release
that is rock solid! We would like to encourage anyone who is willing and
able to spend some time on testing to find and report problems to the
Prelude developers.

The final 1.0.0 release is expected to be released in February.

Prelude-Correlator serves to correlate, in real time, the multiple
events received by Prelude. Several isolated alerts, generated from
different probes, can thus trigger a single correlation alert should the
events be related.


------[ CHANGES ]------

- [Firewall]: The plugin will now report CorrelationAlert for events /
sets of events that appear to have passed through a firewall known to
protect the target machine. If no firewall ever emit block concerning
a given host, then this host is considered un-protected, and there is
no point in reporting CorrelationAlert.

- [OpenSSHAuth]: The plugin has been modified so that it can now
generate a single CorrelationAlert for multiples authentication method
used in a given time slice.

- [Spamhaus]: The plugin has been modified so that it can now generate a
single CorrelationAlert for multiples events received from the same
source.

- [BruteForce]: Various improvement, do not limit the number of events
the plugin is able to report in a single CorrelationAlert.

- [Scan]: do not limit the number of events the plugin is able to report
in a single CorrelationAlert.

- Context initialization now take an optional 'overwrite' argument. This
argument, if set to False, mean that the Context() will be returned
un-modified if it already exist. If it doesn't, it will be created.

- New Context.update() method, which provide exactly the same
functionality as calling Context() with the 'update=True' argument.
This is useful since some plugin need to defer an update to another
place in the code.

- If the context creation/update function is called with an IDMEF
message
parameter, then we automatically call addAlertReference on the context
CorrelationAlert using the provided message as the parameter.

- Make it possible to change context option on update

- Automatically set CorrelationAlert DetectTime : reported
CorrelationAlert DetectTime now match the time of the first event that
was detected.

- Make it possible for plugin to specify a function to be called on
Timer expiration.

- Disable BusinessHour correlation by default since it is very verbose

- Various bug fixes.


------[ SUPPORT ] ------

Improving Prelude is costly, but you can help! We are looking for
organizations that find Prelude useful and wish to contribute back.

Commercial support contracts for Prelude are available, and they help
finance continued maintenance. PreludeIDS Technologies, a privately held
company, is currently funding Prelude maintenance.


------[ DOWNLOAD ]------

http://www.prelude-ids.com/development/download/


------[ CHECKSUM ]------

MD5 : 8315d7401905e5058e2b3b7c37f7e46e
SHA1 : e468dd13447fe52a0f1e562849f89854bc9599dc
SHA256 :
e5d3fc5a379eecc35a280635619e9747e4e8f59c4e2c90d685d60033565bcbf5


------[ OpenPGP key ]------

gpg --keyserver wwwkeys.pgp.net --recv-keys 0x23D2FAC3


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQIcBAABAgAGBQJLYxROAAoJEBHxO34j0vrDXFgP/0ku2Xzaqabvk9QdbykPvruO
HxkN8vc33/GeNBOsSL1LQZhBZngqWLYZeuy4UaLVAvzY5VPtlg/TIyHJcg8DU4VF
nYQH7m48Dbf+zDsR5RgypiTruCrzVmOKQ0pEyy6g7ZZxR07yZAL5Y0BndEe3vYMb
JVtRuOef7TeCc+oehRrZJJCPVopYS7iPpMRLNP/9AwrO8IBJGUyeRGk1BJUxnkri
guel9cjZW5Yg9j95ybBoDjBs7y8+VyiDYSPZuJpFuuRC+9wDBsAMX5lavjNzmcE6
+CBekDIQiS4uqUb/2e1rrQLadVCEdPmeQDYvj0+ixVPgvJ/bYXoLtFuf6eLvaHsy
HgW6WpBaLNhQTGqoe6m/ppMQ/OQQy/M3dkXG9G8cwixDTYXq2EPfblByjy3JVobx
VxlOxncSNuKCiRVQWH6G7MiFzVmYmsI+4VUIHKc+Pzje6uIRu4gLDcF0K6U/lOk/
G5wIMBcy+6hCHbfP+L2Y3cr7WGVgb0OQMojFClnTr6lOO3sJnrhpV6Dzd+OYFnPP
zXfrJVH0zKEqHy6PVzK1yb3oDYGaANO268/kwGPPGKpgGpDLNkGdDSjnWiEj58se
+SlKmQtzIE/Zy3HNoAxk6PHaiC5PrLZYBRz2dMJ8C2yFhapAr/8MJa/cNv/7H/pB
6kX+llenYaEEoBSnQX1z
=3CVx
-----END PGP SIGNATURE-----

-- 
Yoann Vandoorselaere | Directeur Technique/CTO | PreludeIDS Technologies
Tel: +33 (0)1 40 24 65 10                      Fax: +33 (0)1 40 24 65 28
http://www.prelude-ids.com

_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user