Snort Blog: New version of Snort 3 out now (3.1.6.0) — Here are all the updates and fixes

"Joel Esler \(jesler\) via Snort-sigs" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <[email protected]>
> 
> https://blog.snort.org/2021/06/new-version-of-snort-3-out-now-3160.html <https://blog.snort.org/2021/06/new-version-of-snort-3-out-now-3160.html>
> 
> New version of Snort 3 out now (3.1.6.0) — Here are all the updates and fixes
> 
>  <https://1.bp.blogspot.com/-ntj3EkCrSqA/YG83tevX5oI/AAAAAAAAAaU/3s-jMVQHRrwrE7eCWnrgDpEcAjYqnmDZwCPcBGAYYCw/s1500/snort3_social_blog%2Bheader.jpg>
> The SNORTⓇ team recently released a new version of Snort 3 on Snort.org <https://snort.org/snort3> and the Snort 3 GitHub <https://github.com/snort3/snort3/releases/tag/3.1.5.0>.
> 
> Snort 3.1.6.0 contains several new features and bug fixes. Here's a complete rundown of what's new in this version. Users are encouraged to update as soon as possible and to upgrade to Snort 3 if they have not already done so.
> 
>  <>appid: extract auxiliary ip when uri is provided by third-party
> appid: perform detection on request body for HTTP2 traffic.
> appid: remove error message when userappid.conf is not present
> appid: remove unused metadata offset functionality
> appid: support fragmented metadata
> appid: use 32 bits for storing protocol field in RPC port map message
> codecs: geneve - add support for Geneve encapsulation
> codecs: geneve - add vni to alert_csv and alert_json
> codecs: support inner flow NAT
> control: allow compile with shell disabled
> control: clean up cppcheck issues
> control: expose ContrlConn API
> control: refactor control channel management to better handle control responses
> control: remove SHELL compile flag from header
> control: remove unused IdleProcessing functionality
> dce_rpc: SMB multichannel - add smb multichannel file support
> dce_rpc: SMB multichannel - handle negotiate command to create expected flow
> dce_rpc: SMB multichannel - introduce locks
> dce_rpc: SMB multichannel - make session cache global
> dce_rpc: SMB multichannel - own memory tracking in global cache
> dce_rpc: fix warnings
> dce_rpc: handle reload prune for smb session cache
> dce_rpc: store shared pointer of session tracker
> doc: update JS normalizer options
> file_api: increase file count only once per file
> file_api: store processing flow in context
> filters: change rate filter to use network policy id instead of ips policy id
> filters: support rate filter to work with PDUs
> flow: enable support for multiple expected sessions
> FTP: create additional expected session if negotiated IP is different from server IP on packet
> GTP: check protocol type according to gtp version
> host_cache: remove unused lua mock code from the tests
> http2_inspect: don't perform valid sequence check on rst_stream frame
> http2_inspect: improve request line generation and checks
> http2_inspect: rule options and doc clean up
> http2_inspect: track dynamic table memory allocation
> http_inspect: add JS Normalizer to dev_notes
> http_inspect: add JS normalization for external scripts
> http_inspect: additional memory tracking
> http_inspect: extend built-in alerts for Javascript processing
> http_inspect: improve MPSE in HttpJsNorm (script start conditions)
> http_inspect: limit section size target for file processing
> http_inspect: publish event for http/2 request bodies
> http_inspect: support partial detect for Javascripts
> http_inspect: track memory footprint of zlib inflation
> http_inspect: update test mock api
> iec104: delete trailing spaces
> ips_options: fix intrusion alerts generation for tcp rpc PORTMAP traffic when rpc_decode is bound to the flow
> main: add support for resuming particular thread
> main: fix config dump for list-based inspector aliases
> mime: store extra data in stash
> packet_io: enable expected session flags
> protocols: remove inline specifiers for functions defined within a structure declaration
> pub_sub: add get_uri_host() to HttpEvent
> pub_sub: update HttpEvent::get_host to get_authority - now always includes port if there is one
> reputation: daq trace log
> reputation: support auxiliary IP matching upon reload
> RNA: filter DHCP events and some refactoring
> RNA: update last seen time on deleted host rediscovery
> stream: enable support for multiple expected sessions
> stream_tcp: populate flow contents in context for non-wire packets
> time: make Periodic class SO_PUBLIC
> trace: place trace options under the DEBUG_MSGS macro
> utils: fix warning about empty statement
> utils: refactor JSTokenizer
> utils: rework JSNormalizer class
> Snort 3 is the next generation of the Snort Intrusion Prevention System. The GitHub page <https://github.com/snort3/snort3> will walk users through what Snort 3 has to offer and guide users through the steps of getting set up — from download to demo. Users unfamiliar with Snort should start with the Snort Resources page and the Snort 101 video series <https://www.youtube.com/watch?v=W1pb9DFCXLw&ab_channel=CiscoTalosIntelligenceGroup>. 
> 
> You can subscribe <https://www.snort.org/products> to Talos' newest rule detection functionality for as low as $29 a year with a personal account. Be sure and see our business pricing as well here <https://snort.org/products#rule_subscriptions>. Make sure and stay up to date to catch the most emerging threats <https://snort.org/products#rule_subscriptions>.

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
smime.p7s (application/pkcs7-signature, 2.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.