Snort 3 registered ruleset format changes?

Dheeraj Gupta via Snort-sigs <[email protected]>
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <CAOsL98MRfWKq8fmwRoqy5c07CtVSZuMb3L5wWf41STLbBXNTxg@mail.gmail.com>
Hi,

We have observed that in last two ruleset releases (2-Feb and 6-Feb), the
structure of the registered ruleset tar.gz has changed.

In the 2-Feb-2023 release (snortrules-snapshot-31470.tar.gz), only so_rules
were present and a single rules file was present.

In the 6-Feb-2023 release(snortrules-snapshot-31470.tar.gz), the rules
folder has two sub-folders (3.0.0.0) and (3.1.35.0). The former has
multiple rule files while the latter has single rule file
(snort3-file-java.rules)

This is problematic for us because the active rule number has suddenly gone
down from around 40K to 3K and usual alerts have stopped.

Has there been an official change in how rule tar.g are structured or is
this a transient bug?

I have not looked at Talos-LightSPD so can't comment on its structure


Thanks,
Dheeraj

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.