Snort Blog: New version of Snort 3 out now (3.1.6.0) — Here are all the updates and fixes
"Joel Esler \(jesler\) via Snort-sigs" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.sigs |
|---|---|
| Message-ID | <[email protected]> |
> > https://blog.snort.org/2021/06/new-version-of-snort-3-out-now-3160.html <https://blog.snort.org/2021/06/new-version-of-snort-3-out-now-3160.html> > > New version of Snort 3 out now (3.1.6.0) — Here are all the updates and fixes > > <https://1.bp.blogspot.com/-ntj3EkCrSqA/YG83tevX5oI/AAAAAAAAAaU/3s-jMVQHRrwrE7eCWnrgDpEcAjYqnmDZwCPcBGAYYCw/s1500/snort3_social_blog%2Bheader.jpg> > The SNORTⓇ team recently released a new version of Snort 3 on Snort.org <https://snort.org/snort3> and the Snort 3 GitHub <https://github.com/snort3/snort3/releases/tag/3.1.5.0>. > > Snort 3.1.6.0 contains several new features and bug fixes. Here's a complete rundown of what's new in this version. Users are encouraged to update as soon as possible and to upgrade to Snort 3 if they have not already done so. > > <>appid: extract auxiliary ip when uri is provided by third-party > appid: perform detection on request body for HTTP2 traffic. > appid: remove error message when userappid.conf is not present > appid: remove unused metadata offset functionality > appid: support fragmented metadata > appid: use 32 bits for storing protocol field in RPC port map message > codecs: geneve - add support for Geneve encapsulation > codecs: geneve - add vni to alert_csv and alert_json > codecs: support inner flow NAT > control: allow compile with shell disabled > control: clean up cppcheck issues > control: expose ContrlConn API > control: refactor control channel management to better handle control responses > control: remove SHELL compile flag from header > control: remove unused IdleProcessing functionality > dce_rpc: SMB multichannel - add smb multichannel file support > dce_rpc: SMB multichannel - handle negotiate command to create expected flow > dce_rpc: SMB multichannel - introduce locks > dce_rpc: SMB multichannel - make session cache global > dce_rpc: SMB multichannel - own memory tracking in global cache > dce_rpc: fix warnings > dce_rpc: handle reload prune for smb session cache > dce_rpc: store shared pointer of session tracker > doc: update JS normalizer options > file_api: increase file count only once per file > file_api: store processing flow in context > filters: change rate filter to use network policy id instead of ips policy id > filters: support rate filter to work with PDUs > flow: enable support for multiple expected sessions > FTP: create additional expected session if negotiated IP is different from server IP on packet > GTP: check protocol type according to gtp version > host_cache: remove unused lua mock code from the tests > http2_inspect: don't perform valid sequence check on rst_stream frame > http2_inspect: improve request line generation and checks > http2_inspect: rule options and doc clean up > http2_inspect: track dynamic table memory allocation > http_inspect: add JS Normalizer to dev_notes > http_inspect: add JS normalization for external scripts > http_inspect: additional memory tracking > http_inspect: extend built-in alerts for Javascript processing > http_inspect: improve MPSE in HttpJsNorm (script start conditions) > http_inspect: limit section size target for file processing > http_inspect: publish event for http/2 request bodies > http_inspect: support partial detect for Javascripts > http_inspect: track memory footprint of zlib inflation > http_inspect: update test mock api > iec104: delete trailing spaces > ips_options: fix intrusion alerts generation for tcp rpc PORTMAP traffic when rpc_decode is bound to the flow > main: add support for resuming particular thread > main: fix config dump for list-based inspector aliases > mime: store extra data in stash > packet_io: enable expected session flags > protocols: remove inline specifiers for functions defined within a structure declaration > pub_sub: add get_uri_host() to HttpEvent > pub_sub: update HttpEvent::get_host to get_authority - now always includes port if there is one > reputation: daq trace log > reputation: support auxiliary IP matching upon reload > RNA: filter DHCP events and some refactoring > RNA: update last seen time on deleted host rediscovery > stream: enable support for multiple expected sessions > stream_tcp: populate flow contents in context for non-wire packets > time: make Periodic class SO_PUBLIC > trace: place trace options under the DEBUG_MSGS macro > utils: fix warning about empty statement > utils: refactor JSTokenizer > utils: rework JSNormalizer class > Snort 3 is the next generation of the Snort Intrusion Prevention System. The GitHub page <https://github.com/snort3/snort3> will walk users through what Snort 3 has to offer and guide users through the steps of getting set up — from download to demo. Users unfamiliar with Snort should start with the Snort Resources page and the Snort 101 video series <https://www.youtube.com/watch?v=W1pb9DFCXLw&ab_channel=CiscoTalosIntelligenceGroup>. > > You can subscribe <https://www.snort.org/products> to Talos' newest rule detection functionality for as low as $29 a year with a personal account. Be sure and see our business pricing as well here <https://snort.org/products#rule_subscriptions>. Make sure and stay up to date to catch the most emerging threats <https://snort.org/products#rule_subscriptions>. _______________________________________________ Snort-sigs mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
smime.p7s
(application/pkcs7-signature, 2.9 KB) - not displayed