Using LightSPD rules when we have custom config

Dheeraj Gupta via Snort-users <[email protected]> Wed, 14 Aug 2024 12:53:48 +0530
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CAOsL98NVzso47zPWJ4U_Kje-TWPmnLwvOqLPSQM-3uXnULN__g@mail.gmail.com>
Hi,

I have been trying to understand usage of LightSPD rules in order to switch
to using them. I had earlier too posted on the same topic in this
mailing-list ( https://seclists.org/snort/2024/q1/44 ).

My understanding now is that in order to use the LightSPD rules, we do the
following:

- Find out our snort version (V1)
- Unzip the LightSPD tarball and open manifest.json. Then lookup the latest
version entry <= V1
- Specify architectures -> YOUR_ARCH -> modules_path to --plugin-path
switch in snort command
- Specify policies_path/POLICY_NAME.lua as value to -c switch in snort
command line

However, we have some customized configuration in our environment (afpacket
daq, perf_monitor, alert_json, home_net,  port spec etc) which we would
like to reuse when updating rules.  What is the standard procedure when
using LightSPD with custom configuration? I would not like to specify all
configuration options in command line but use lua files for the same

- Do we define our own config file and keep an include() which is updated
with appropriate policy based on LightSPD at every update? or can we use
command line switches to specify base and custom policy files?
- How can we disable certain rules (in pulledpork we can update
disablesid.conf) or enable or modify the rules when deploying rule updates?
Would this be done in our lua config and can we use rule sids or gids
directly to enable/disable?
- Is there a standard tool (something like pulledpork) which can automate
extraction of paths from manifest?

Regards,
Dheeraj

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette