Migration to Snort 3

Andrew Welham <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Hi,

I originally stayed away from Snort 2.x as all the reviews said it 
needed some modernisation. I moved to Suricata 5 which works well. I 
looked to upgrade to Suricata 6 but due to some performance issues with 
the product since V6, and the bugs don’t look to be getting resolved, 
plus snort 3 rewrite looks like a time to switch over.

I built snort 3 (ubuntu 22.04)and have been testing this week. I’m 
running in inline mode with NFQ.

Coming from a Suricata background I treated Snort like Suricata, which 
looks to have been a mistake.

I have come across a few issues, so would welcome any input from the 
Snort experts.

Firstly I can’t switch to a non-root user for snort since I started to 
use NFQ, Is there any way around this ?

I take it as I’m using NFQ I don’t need to have the interfaces in 
promiscuous mode?

My biggest mistake looks to have treated snort like Suricata when it 
came to rules.

Initially I downloaded the community rules, but also decided to use the 
snort rules for snort 2.9 from Emerging threats and converting them with 
snort2lua -c "$InputFile" -r "$OutputFile"

Then a little more editing to change the # alert to block or what ever I 
wanted. As I noticed that pulledpork is in alpha status and is missing 
capabilities formodifying rules. I used to use the capability with the 
Suricata updater to change rules so I could customise the rules for each 
subnet. This way I gained maximum flexibility and would only disable a 
rule if it affected all subnets.

I have subsequently registered and have more rules snort 3 official 
rules , although I am a little confused by the Talos files which need to 
be compiled, even though there are extra rules there. From my reading 
these are to protect against areas rules cannot meet? Yet these are 
architecture dependant. Any pages I can get some background on this 
from? There also seems to be a Talos_LightSPD and snapshot files? Which 
ones should I use? also if I want to grab the file automatically how do 
I know the next filename?

Sorry for the basic questions.

Andrew

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.