Snort 3.1.82.0 is available now and introduces the new Snort ML feature.

"Brendan Bell \(brebell\) via Snort-users" <[email protected]> Fri, 15 Mar 2024 14:13:22 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <PH7PR11MB86004C93767D4E25C31D91C7B2282@PH7PR11MB8600.namprd11.prod.outlook.com>
SnortML is a machine learning-based detection engine for the Snort intrusion prevention system. At a high level, there are two components to this new detection engine. The first component is the snort_ml_engine itself, which loads pre-trained machine learning models, instantiates classifiers based on these models and then makes the classifiers available for detection. The second is the snort_ml inspector, which subscribes to data provided by Snort service inspectors, passes the data to classifiers, and then acts on the output of the classifiers.

You can learn more about Snort ML here: https://blog.snort.org/2024/03/talos-launching-new-machine-learning.html

Optional dependencies:

  *   To use Snort ML(snort_ml inspector), please download libML<https://github.com/snort3/libml> and Snort Rules (Talos_LightSPD) from version 2024-03-13-001 onwards

Changes in this release since 3.1.82.0:

  *   appid: broadcast commands with ctrlcon
  *   appid: change eve pattern matching logic
  *   appid: replaced warning log with logging api for CBD
  *   file_api: do not clear the file capture and user file data pointers when updating the verdict from the cache
  *   filters: updated dyn array with vector
  *   flow: updated flow_data linklist with STL container
  *   framework: validate parameter of number type in a string form
  *   kaizen: rename to Snort ML
  *   main: clear lua stack when registering commands in a shell
  *   main: reset main-thread stats from the main thread
  *   main: update limits help
  *   packet_capture: add packet capturing per tenant
  *   sfip: remove references to unused mode feature
  *   sfip: zero out var/node pointers after operations to remedy heap-use-after-free on reload
  *   smb: fix for improper session cache destruction in tterm during config reload
  *   snort2lua: change deprecated use of ptr_fn to lambda
  *   stats: fix timing stats
  *   stats: perf improvement changes
  *   stream: remove splitter from session before inspectors
  *   stream_tcp: add reasons for drops due to trims
  *   stream_tcp: implement support for proxy mode normalization behavior
  *   stream_tcp: update documentation for stream TCP alerts to include the new 129:21 and 129:22 alerts
  *   trace: add tenants logging

If you'd like to connect with other Snort users please join our Discord:
https://discord.gg/cbhpQ7bd

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette