Re: SnortML

Ron Jenkins via Snort-users <[email protected]> Mon, 1 Apr 2024 17:03:02 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <SN6PR13MB2432CD6CCB58FDBE8E8BCD8AE13F2@SN6PR13MB2432.namprd13.prod.outlook.com>
Looking for any documentation with ML running live in IDS daemon mode, not running against PCAPs.


Thx

From: Nick Godwod <[email protected]>
Sent: Monday, April 1, 2024 11:58 AM
To: Ron Jenkins <[email protected]>
Cc: Patrick Mullen (pamullen) <[email protected]>; Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected]>; [email protected]
Subject: Re: [Snort-users] SnortML


CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders.
You should be able to find modules on github like this.
Lots of folks run a preconfigured version.
Sent from my iPhone


On Apr 1, 2024, at 10:45, Ron Jenkins via Snort-users <[email protected]<mailto:[email protected]>> wrote:

Good morning

Are there any already configured models that I can download for use with Snort in IDS daemon mode?


Thank you!

From: Patrick Mullen (pamullen) <[email protected]<mailto:[email protected]>>
Sent: Thursday, March 21, 2024 6:51 AM
To: Ron Jenkins <[email protected]<mailto:[email protected]>>; Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected]<mailto:[email protected]>>
Cc: Nihal Desai (nihdesai) <[email protected]<mailto:[email protected]>>; [email protected]<mailto:[email protected]>
Subject: RE: [Snort-users] SnortML


CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders.
Ron,

You will need to create your own model file for doing the detection itself.

There is a blog post about the new feature and how to create a model using tools in the repository.

https://blog.snort.org/2024/03/talos-launching-new-machine-learning.html

It’s great to see someone using the tech! Let me know if you’re able to create your own model and how it goes.


Thanks,

~Patrick

From: Ron Jenkins <[email protected]<mailto:[email protected]>>
Sent: Wednesday, March 20, 2024 8:38 AM
To: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected]<mailto:[email protected]>>
Cc: Nihal Desai (nihdesai) <[email protected]<mailto:[email protected]>>; [email protected]<mailto:[email protected]>
Subject: Re: [Snort-users] SnortML

Good morning

Success!  See below.  I re-ran the config for Snort v3.1.82 and now it shows LibML: ON; see below.

Are there any detail documentation in using the new SnortML?  Is there a default setup for it?


Thank you!!!

<image001.png>

<image002.png>


<image003.png>



From: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected]<mailto:[email protected]>>
Sent: Wednesday, March 20, 2024 3:33 AM
To: Ron Jenkins <[email protected]<mailto:[email protected]>>
Cc: Nihal Desai (nihdesai) <[email protected]<mailto:[email protected]>>; [email protected]<mailto:[email protected]>
Subject: Re: SnortML


CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders.
Hi Ron!

Now try to add a line "#include <cstdint>” into the file libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc<http://spectrogram.cc> on the line 20 and make previous steps I’ve mentioned in the previous email.

Best Wishes

Yurii Chalov

On 19 Mar 2024, at 17:43, Ron Jenkins <[email protected]<mailto:[email protected]>> wrote:

Still no luck, see below.


Thanks

[  0%] Built target clog
[  0%] Built target normalization
[  0%] Built target absl_log_severity
[  0%] Built target pthreadpool
[  0%] Built target absl_spinlock_wait
[  0%] Built target absl_strerror
[  0%] Built target absl_int128
[  4%] Built target absl_time_zone
[  4%] Built target absl_exponential_biased
[  4%] Built target absl_flags_commandlineflag_internal
[  4%] Built target absl_civil_time
[  4%] Built target farmhash
[  4%] Built target fft2d_fftsg
[  4%] Built target ruy_wait
[  4%] Built target flatbuffers
[  4%] Built target ruy_system_aligned_alloc
[  4%] Built target ruy_profiler_instrumentation
[  4%] Built target ruy_denormal
[  4%] Built target ruy_apply_multiplier
[  4%] Built target ruy_have_built_path_for_avx512
[  4%] Built target ruy_have_built_path_for_avx2_fma
[  4%] Built target ruy_have_built_path_for_avx
[  4%] Built target allocator
[  4%] Built target microparams_init
[  4%] Built target cpuinfo
[  4%] Built target logging
[  4%] Built target cache
[  4%] Built target mutex
[  4%] Built target absl_raw_logging_internal
[  4%] Built target operators
[  8%] Built target subgraph
[  8%] Built target fft2d_fftsg2d
[  8%] Built target ruy_cpuinfo
[ 13%] Built target ruy_prepacked_cache
[ 17%] Built target ruy_allocator
[ 17%] Built target ruy_block_map
[ 17%] Built target ruy_blocking_counter
[ 17%] Built target post-operation
[ 17%] Built target absl_base
[ 17%] Built target absl_throw_delegate
[ 17%] Built target absl_debugging_internal
[ 17%] Built target absl_bad_optional_access
[ 21%] Built target absl_bad_variant_access
[ 21%] Built target absl_city
[ 21%] Built target absl_low_level_hash
[ 21%] Built target absl_cordz_functions
[ 21%] Built target ruy_tune
[ 21%] Built target ruy_thread_pool
[ 21%] Built target absl_malloc_internal
[ 21%] Built target absl_stacktrace
[ 21%] Built target absl_demangle_internal
[ 21%] Built target absl_strings_internal
[ 21%] Built target absl_graphcycles_internal
[ 21%] Built target ruy_pack_arm
[ 21%] Built target ruy_kernel_arm
[ 21%] Built target ruy_kernel_avx512
[ 21%] Built target ruy_pack_avx512
[ 21%] Built target ruy_kernel_avx2_fma
[ 21%] Built target ruy_pack_avx2_fma
[ 21%] Built target ruy_kernel_avx
[ 21%] Built target ruy_pack_avx
[ 21%] Built target ruy_ctx
[ 21%] Built target ruy_context
[ 21%] Built target ruy_trmul
[ 21%] Built target absl_strings
[ 21%] Built target ruy_context_get_ctx
[ 21%] Built target ruy_prepare_packed_matrices
[ 21%] Built target absl_symbolize
[ 21%] Built target absl_flags_commandlineflag
[ 21%] Built target absl_time
[ 26%] Built target absl_str_format_internal
[ 26%] Built target absl_hash
[ 26%] Built target ruy_frontend
[ 26%] Built target absl_cord_internal
[ 26%] Built target absl_flags_marshalling
[ 26%] Built target absl_synchronization
[ 26%] Built target absl_flags_private_handle_accessor
[ 26%] Built target absl_flags_program_name
[ 26%] Built target absl_hashtablez_sampler
[ 26%] Built target absl_cordz_handle
[ 26%] Built target absl_flags_config
[ 26%] Built target absl_raw_hash_set
[ 26%] Built target absl_cordz_info
[ 26%] Built target absl_flags_internal
[ 26%] Built target absl_cord
[ 69%] Built target XNNPACK
[ 69%] Built target absl_flags_reflection
[ 69%] Built target absl_status
[ 73%] Built target absl_flags
[ 73%] Building CXX object vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/add.cc.o
[ 73%] Building CXX object vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/internal/spectrogram.cc.o
[ 73%] Building CXX object vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/add_n.cc.o
[ 73%] Building CXX object vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/arg_min_max.cc.o
/downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:46:22: error: ‘uint32_t’ was not declared in this scope
  46 | inline int Log2Floor(uint32_t n) {
     |                      ^~~~~~~~
/downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:20:1: note: ‘uint32_t’ is defined in header ‘<cstdint>’; did you forget to ‘#include <cstdint>’?
  19 | #include <math.h>
 +++ |+#include <cstdint>
  20 |
/downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:61:24: error: ‘uint32_t’ was not declared in this scope
  61 | inline int Log2Ceiling(uint32_t n) {
     |                        ^~~~~~~~
/downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:61:24: note: ‘uint32_t’ is defined in header ‘<cstdint>’; did you forget to ‘#include <cstdint>’?
/downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:69:8: error: ‘uint32_t’ does not name a type
  69 | inline uint32_t NextPowerOfTwo(uint32_t value) {
     |        ^~~~~~~~
/downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:69:8: note: ‘uint32_t’ is defined in header ‘<cstdint>’; did you forget to ‘#include <cstdint>’?
/downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc: In member function ‘bool tflite::internal::Spectrogram::Initialize(const std::vector<double>&, int)’:
/downloads/snort3/libml-1.0.0/vendor/tensorflow/tensorflow/lite/kernels/internal/spectrogram.cc:92:17: error: ‘NextPowerOfTwo’ was not declared in this scope
  92 |   fft_length_ = NextPowerOfTwo(window_length_);
     |                 ^~~~~~~~~~~~~~
At global scope:
cc1plus: note: unrecognized command-line option ‘-Wno-unknown-attributes’ may have been intended to silence earlier diagnostics
make[2]: *** [vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/build.make:566: vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/kernels/internal/spectrogram.cc.o] Error 1
make[2]: *** Waiting for unfinished jobs....
make[1]: *** [CMakeFiles/Makefile2:6169: vendor/tensorflow/tensorflow/lite/CMakeFiles/tensorflow-lite.dir/all] Error 2
make: *** [Makefile:136: all] Error 2


-----Original Message-----
From: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco) <[email protected]<mailto:[email protected]>>
Sent: Tuesday, March 19, 2024 11:18 AM
To: Ron Jenkins <[email protected]<mailto:[email protected]>>
Cc: Nihal Desai (nihdesai) <[email protected]<mailto:[email protected]>>; [email protected]<mailto:[email protected]>
Subject: Re: SnortML

CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders.

Hey Ron!

So as I see, the fix of this problem is in progress. Anyway, you can try to fix using these steps

1. run './configure.sh'
2. run ‘cd build’
3. in the file ‘CMakeCache.txt’ find 'CMAKE_C_FLAGS:STRING’ and 'CMAKE_CXX_FLAGS:STRING’. Add to these fields '-Wno-error=stringop-overflow=‘

The example is below:
CMAKE_C_FLAGS:STRING=-Wno-error=stringop-overflow=
CMAKE_CXX_FLAGS:STRING=-Wno-error=stringop-overflow=

4. run 'sudo make -j$(nproc) install’

Best wishes

Yurii Chalov


On 19 Mar 2024, at 16:41, Ron Jenkins <[email protected]<mailto:[email protected]>> wrote:

Please see below.
 Thanks
[  0%] Built target normalization
[  0%] Built target clog
[  0%] Built target pthreadpool
[  0%] Built target absl_log_severity
[  0%] Built target absl_spinlock_wait [  0%] Built target
absl_strerror [  0%] Built target absl_int128 [  4%] Built target
absl_time_zone [  4%] Built target absl_exponential_biased [  4%]
Built target absl_flags_commandlineflag_internal
[  4%] Built target absl_civil_time
[  4%] Built target farmhash
[  4%] Built target fft2d_fftsg
[  4%] Built target ruy_system_aligned_alloc [  4%] Built target
ruy_wait [  4%] Building CXX object
vendor/flatbuffers/CMakeFiles/flatbuffers.dir/src/reflection.cpp.o
[  4%] Built target ruy_profiler_instrumentation [  4%] Built target
ruy_apply_multiplier [  4%] Built target ruy_denormal [  4%] Built
target ruy_have_built_path_for_avx512 [  4%] Built target
ruy_have_built_path_for_avx2_fma [  4%] Built target
ruy_have_built_path_for_avx [  4%] Built target allocator [  4%] Built
target cpuinfo [  4%] Built target microparams_init [  4%] Built
target logging [  4%] Built target cache [  8%] Built target subgraph
[  8%] Built target operators [  8%] Built target mutex [  8%] Built
target absl_raw_logging_internal [  8%] Built target fft2d_fftsg2d [
8%] Built target ruy_cpuinfo [ 13%] Built target ruy_prepacked_cache [
17%] Built target ruy_allocator [ 17%] Built target ruy_block_map [
17%] Built target ruy_blocking_counter [ 17%] Built target
post-operation [ 17%] Built target absl_base [ 17%] Built target
absl_throw_delegate [ 17%] Built target absl_debugging_internal [ 17%]
Built target absl_bad_optional_access [ 21%] Built target
absl_bad_variant_access [ 21%] Built target absl_city [ 21%] Built
target absl_low_level_hash [ 21%] Built target absl_cordz_functions [
21%] Built target ruy_tune [ 21%] Built target ruy_thread_pool [ 21%]
Built target absl_malloc_internal [ 21%] Built target absl_stacktrace
[ 21%] Built target absl_strings_internal [ 21%] Built target
absl_demangle_internal [ 21%] Built target ruy_kernel_arm [ 21%] Built
target absl_graphcycles_internal [ 21%] Built target ruy_pack_arm [
21%] Built target ruy_kernel_avx512 [ 21%] Built target
ruy_pack_avx512 [ 21%] Built target ruy_kernel_avx2_fma [ 21%] Built
target ruy_kernel_avx [ 21%] Built target ruy_pack_avx2_fma [ 21%]
Building CXX object vendor/ruy/ruy/CMakeFiles/ruy_ctx.dir/ctx.cc.o
[ 65%] Built target XNNPACK
[ 65%] Built target ruy_pack_avx
[ 65%] Built target absl_strings
[ 65%] Built target absl_symbolize
[ 65%] Built target absl_time
[ 65%] Built target absl_flags_commandlineflag [ 69%] Built target
absl_str_format_internal [ 69%] Built target absl_hash [ 69%] Built
target absl_cord_internal [ 69%] Built target absl_synchronization [
69%] Built target absl_flags_marshalling [ 69%] Built target
absl_flags_private_handle_accessor
[ 69%] Built target absl_cordz_handle
[ 69%] Built target absl_hashtablez_sampler [ 69%] Built target
absl_flags_program_name [ 69%] Built target absl_cordz_info [ 69%]
Built target absl_raw_hash_set [ 69%] Built target absl_flags_config [
69%] Built target absl_cord [ 69%] Built target absl_flags_internal [
69%] Built target absl_flags_reflection [ 69%] Built target
absl_status [ 73%] Built target absl_flags [ 73%] Linking CXX static
library libruy_ctx.a [ 73%] Built target ruy_ctx [ 73%] Building CXX
object vendor/ruy/ruy/CMakeFiles/ruy_context.dir/context.cc.o
[ 73%] Building CXX object
vendor/ruy/ruy/CMakeFiles/ruy_trmul.dir/trmul.cc.o
[ 73%] Building CXX object
vendor/ruy/ruy/CMakeFiles/ruy_prepare_packed_matrices.dir/prepare_pack
ed_matrices.cc.o [ 73%] Linking CXX static library
libruy_prepare_packed_matrices.a [ 73%] Built target
ruy_prepare_packed_matrices [ 73%] Linking CXX static library
libruy_trmul.a [ 73%] Linking CXX static library libruy_context.a [
73%] Built target ruy_trmul [ 73%] Built target ruy_context [ 73%]
Building CXX object
vendor/ruy/ruy/CMakeFiles/ruy_frontend.dir/frontend.cc.o
[ 73%] Building CXX object
vendor/ruy/ruy/CMakeFiles/ruy_context_get_ctx.dir/context_get_ctx.cc.o
In file included from /usr/include/c++/13/string:51,
                from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/base.h:41,
                from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/array.h:20,
                from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/flatbuffers.h:22,
                from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/reflection_generated.h:7,
                from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/include/flatbuffers/reflection.h:25,
                from /downloads/snort3/libml-1.0.0/vendor/flatbuffers/src/reflection.cpp:17:
In static member function ‘static _Up* std::__copy_move<_IsMove, true, std::random_access_iterator_tag>::__copy_m(_Tp*, _Tp*, _Up*) [with _Tp = const unsigned char; _Up = unsigned char; bool _IsMove = false]’,
   inlined from ‘_OI std::__copy_move_a2(_II, _II, _OI) [with bool _IsMove = false; _II = const unsigned char*; _OI = unsigned char*]’ at /usr/include/c++/13/bits/stl_algobase.h:506:30,
   inlined from ‘_OI std::__copy_move_a1(_II, _II, _OI) [with bool _IsMove = false; _II = const unsigned char*; _OI = unsigned char*]’ at /usr/include/c++/13/bits/stl_algobase.h:533:42,
   inlined from ‘_OI std::__copy_move_a(_II, _II, _OI) [with bool _IsMove = false; _II = const unsigned char*; _OI = unsigned char*]’ at /usr/include/c++/13/bits/stl_algobase.h:540:31,
   inlined from ‘_OI std::copy(_II, _II, _OI) [with _II = const unsigned char*; _OI = unsigned char*]’ at /usr/include/c++/13/bits/stl_algobase.h:633:7,
   inlined from ‘static _ForwardIterator std::__uninitialized_copy<true>::__uninit_copy(_InputIterator, _InputIterator, _ForwardIterator) [with _InputIterator = const unsigned char*; _ForwardIterator = unsigned char*]’ at /usr/include/c++/13/bits/stl_uninitialized.h:147:27,
   inlined from ‘_ForwardIterator std::uninitialized_copy(_InputIterator, _InputIterator, _ForwardIterator) [with _InputIterator = const unsigned char*; _ForwardIterator = unsigned char*]’ at /usr/include/c++/13/bits/stl_uninitialized.h:185:15,
   inlined from ‘_ForwardIterator std::__uninitialized_copy_a(_InputIterator, _InputIterator, _ForwardIterator, allocator<_Tp>&) [with _InputIterator = const unsigned char*; _ForwardIterator = unsigned char*; _Tp = unsigned char]’ at /usr/include/c++/13/bits/stl_uninitialized.h:373:37,
   inlined from ‘void std::vector<_Tp, _Alloc>::_M_range_insert(iterator, _ForwardIterator, _ForwardIterator, std::forward_iterator_tag) [with _ForwardIterator = const unsigned char*; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/vector.tcc:814:38,
   inlined from ‘std::vector<_Tp, _Alloc>::iterator std::vector<_Tp, _Alloc>::insert(const_iterator, _InputIterator, _InputIterator) [with _InputIterator = const unsigned char*; <template-parameter-2-2> = void; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:1483:19,
   inlined from ‘const uint8_t* flatbuffers::AddFlatBuffer(std::vector<unsigned char>&, const uint8_t*, size_t)’ at /downloads/snort3/libml-1.0.0/vendor/flatbuffers/src/reflection.cpp:365:17:
/usr/include/c++/13/bits/stl_algobase.h:437:30: error: ‘void* __builtin_memcpy(void*, const void*, long unsigned int)’ writing between 2 and 9223372036854775803 bytes into a region of size 0 overflows the destination [-Werror=stringop-overflow=]
 437 |             __builtin_memmove(__result, __first, sizeof(_Tp) * _Num);
     |             ~~~~~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
In file included from /usr/include/x86_64-linux-gnu/c++/13/bits/c++allocator.h:33,
                from /usr/include/c++/13/bits/allocator.h:46,
                from /usr/include/c++/13/string:43:
In member function ‘_Tp* std::__new_allocator<_Tp>::allocate(size_type, const void*) [with _Tp = unsigned char]’,
   inlined from ‘static _Tp* std::allocator_traits<std::allocator<_CharT> >::allocate(allocator_type&, size_type) [with _Tp = unsigned char]’ at /usr/include/c++/13/bits/alloc_traits.h:482:28,
   inlined from ‘std::_Vector_base<_Tp, _Alloc>::pointer std::_Vector_base<_Tp, _Alloc>::_M_allocate(std::size_t) [with _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:378:33,
   inlined from ‘void std::vector<_Tp, _Alloc>::_M_range_insert(iterator, _ForwardIterator, _ForwardIterator, std::forward_iterator_tag) [with _ForwardIterator = const unsigned char*; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/vector.tcc:805:40,
   inlined from ‘std::vector<_Tp, _Alloc>::iterator std::vector<_Tp, _Alloc>::insert(const_iterator, _InputIterator, _InputIterator) [with _InputIterator = const unsigned char*; <template-parameter-2-2> = void; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:1483:19,
   inlined from ‘const uint8_t* flatbuffers::AddFlatBuffer(std::vector<unsigned char>&, const uint8_t*, size_t)’ at /downloads/snort3/libml-1.0.0/vendor/flatbuffers/src/reflection.cpp:365:17:
/usr/include/c++/13/bits/new_allocator.h:151:55: note: at offset [-9223372036854775808, -4] into destination object of size [4, 9223372036854775807] allocated by ‘operator new’
 151 |         return static_cast<_Tp*>(_GLIBCXX_OPERATOR_NEW(__n * sizeof(_Tp)));
     |                                                       ^
[ 73%] Linking CXX static library libruy_frontend.a [ 73%] Built
target ruy_frontend [ 73%] Linking CXX static library
libruy_context_get_ctx.a [ 73%] Built target ruy_context_get_ctx At
global scope:
cc1plus: note: unrecognized command-line option
‘-Wno-unknown-attributes’ may have been intended to silence earlier
diagnostics
cc1plus: all warnings being treated as errors
make[2]: ***
[vendor/flatbuffers/CMakeFiles/flatbuffers.dir/build.make:104:
vendor/flatbuffers/CMakeFiles/flatbuffers.dir/src/reflection.cpp.o]
Error 1
make[1]: *** [CMakeFiles/Makefile2:4624:
vendor/flatbuffers/CMakeFiles/flatbuffers.dir/all] Error 2
make: *** [Makefile:136: all] Error 2
 From: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco)
<[email protected]<mailto:[email protected]>>
Sent: Tuesday, March 19, 2024 10:37 AM
To: Ron Jenkins <[email protected]<mailto:[email protected]>>
Cc: Nihal Desai (nihdesai) <[email protected]<mailto:[email protected]>>;
[email protected]<mailto:[email protected]>
Subject: Re: SnortML
CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders.
Hi Ron!
I looked at the output which you sent before, but I don’t see any
errors, just warnings. Could you please make a build using a command
"sudo make -j$(nproc) install 2>&1 | tee error.log” and send a file
“error.log”. I will see here what’s happening  Best wishes  Yurii
Chalov


On 19 Mar 2024, at 16:33, Ron Jenkins <[email protected]<mailto:[email protected]>> wrote:
????   From: Nihal Desai (nihdesai) <[email protected]<mailto:[email protected]>>
Sent: Tuesday, March 19, 2024 10:25 AM
To: Ron Jenkins <[email protected]<mailto:[email protected]>>;
[email protected]<mailto:[email protected]>
Cc: Yurii Chalov -X (ychalov - SOFTSERVE INC at Cisco)
<[email protected]<mailto:[email protected]>>
Subject: Re: SnortML
CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders.
+ Yuri
--
V/r
Nihal N. Desai
From: Ron Jenkins <[email protected]<mailto:[email protected]>>
Date: Monday, March 18, 2024 at 7:38 PM
To: Nihal Desai (nihdesai) <[email protected]<mailto:[email protected]>>,
[email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>>
Subject: RE: SnortML
Please see below.
cmake version 3.28.3
c++ (Ubuntu 13.2.0-17ubuntu2) 13.2.0
 Thanks
In member function ‘_Tp* std::__new_allocator<_Tp>::allocate(size_type, const void*) [with _Tp = unsigned char]’,
   inlined from ‘static _Tp* std::allocator_traits<std::allocator<_CharT> >::allocate(allocator_type&, size_type) [with _Tp = unsigned char]’ at /usr/include/c++/13/bits/alloc_traits.h:482:28,
   inlined from ‘std::_Vector_base<_Tp, _Alloc>::pointer std::_Vector_base<_Tp, _Alloc>::_M_allocate(std::size_t) [with _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:378:33,
   inlined from ‘void std::vector<_Tp, _Alloc>::_M_range_insert(iterator, _ForwardIterator, _ForwardIterator, std::forward_iterator_tag) [with _ForwardIterator = const unsigned char*; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/vector.tcc:805:40,
   inlined from ‘std::vector<_Tp, _Alloc>::iterator std::vector<_Tp, _Alloc>::insert(const_iterator, _InputIterator, _InputIterator) [with _InputIterator = const unsigned char*; <template-parameter-2-2> = void; _Tp = unsigned char; _Alloc = std::allocator<unsigned char>]’ at /usr/include/c++/13/bits/stl_vector.h:1483:19,
   inlined from ‘const uint8_t* flatbuffers::AddFlatBuffer(std::vector<unsigned char>&, const uint8_t*, size_t)’ at /downloads/snort3/libml-1.0.0/vendor/flatbuffers/src/reflection.cpp:365:17:
/usr/include/c++/13/bits/new_allocator.h:151:55: note: at offset [-9223372036854775808, -4] into destination object of size [4, 9223372036854775807] allocated by ‘operator new’
 151 |         return static_cast<_Tp*>(_GLIBCXX_OPERATOR_NEW(__n * sizeof(_Tp)));
     |                                                       ^
At global scope:
cc1plus: note: unrecognized command-line option
‘-Wno-unknown-attributes’ may have been intended to silence earlier
diagnostics
cc1plus: all warnings being treated as errors
make[2]: ***
[vendor/flatbuffers/CMakeFiles/flatbuffers.dir/build.make:104:
vendor/flatbuffers/CMakeFiles/flatbuffers.dir/src/reflection.cpp.o]
Error 1
make[1]: *** [CMakeFiles/Makefile2:4624:
vendor/flatbuffers/CMakeFiles/flatbuffers.dir/all] Error 2
make: *** [Makefile:136: all] Error 2
root@ids-sensor2:/downloads/snort3/libml-1.0.0/build#<mailto:root@ids-sensor2:/downloads/snort3/libml-1.0.0/build>
From: Nihal Desai (nihdesai) <[email protected]<mailto:[email protected]>>
Sent: Monday, March 18, 2024 4:34 PM
To: Ron Jenkins <[email protected]<mailto:[email protected]>>;
[email protected]<mailto:[email protected]>
Subject: Re: SnortML
CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders.
Hey Ron,
Thanks for reporting the issue.
Can you provide the output of the error? I don’t see it in the screenshot here.
What version of cmake and c++ compiler are you using?
Thanks!
--
V/r
Nihal N. Desai
From: Snort-users <[email protected]<mailto:[email protected]>> on behalf of
Ron Jenkins via Snort-users <[email protected]<mailto:[email protected]>>
Date: Monday, March 18, 2024 at 8:42 AM
To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>>
Subject: [Snort-users] SnortML
Good morning
Is there any document on installing from source released yet?  I am also getting the below when performing ‘make -j$(nproc) install’.
 Thank you!
<image001.png>
Ron Jenkins (Owner / Senior Architect / Cyber Security Consultant)
RMJ Consulting, LLC. " Supporting Companies with their Technology needs"
11715 Bricksome Ave STE B-7
Baton Rouge, LA 70816
Direct. 225-448-5214 Ext #101
Cell. 225-931-1632
Web. http://www.rmjconsulting.net
Log Siphon. http://www.logsiphon.com
Linkedin. www.linkedin.com/in/ronmjenkins/<http://www.linkedin.com/in/ronmjenkins/>
Twitter: www.twitter.com/RMJConsulting<http://www.twitter.com/RMJConsulting>
Facebook: www.facebook.com/rmjcsconsulting<http://www.facebook.com/rmjcsconsulting>
 PRIVILEGED & CONFIDENTIAL COMMUNICATION:
The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.
PRIVILEGED & CONFIDENTIAL COMMUNICATION:
The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.
PRIVILEGED & CONFIDENTIAL COMMUNICATION:
The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.  PRIVILEGED & CONFIDENTIAL COMMUNICATION:
The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.

PRIVILEGED & CONFIDENTIAL COMMUNICATION:
The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.


PRIVILEGED & CONFIDENTIAL COMMUNICATION:
The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.

PRIVILEGED & CONFIDENTIAL COMMUNICATION:
The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.
_______________________________________________
Snort-users mailing list
[email protected]<mailto:[email protected]>
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

   To unsubscribe, send an email to:
   [email protected]<mailto:[email protected]>

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
PRIVILEGED & CONFIDENTIAL COMMUNICATION:
The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette