Monday, July 14, 2014

Snort Subscriber Rule Set Update

In the post about the new website, I had a section about our new rule packaging structure.  Let me expand on it a bit so that everyone understands.

The Rule Set is broken down like this:

  • Community
    • GPLv2
    • Built from your submissions, tested and approved, by us.
    • Published daily
    • Always free.
  • Registered
    • Snort Subscriber Rule Set License (No re-use without fee, and no distribution without fee)
    • 30-day delay on new content
    • Updated content (outside the 30 day window) is updated every release
    • Published at least twice a week, Tuesdays and Thursdays.  
    • Free, with license agreement on Snort.org
    • Contains the Community Ruleset
  • Subscriber
    • Snort Subscriber Rule Set License (No re-use without fee, and no distribution without fee)
    • Released at the same time as content for the Cisco NGIPS (Sourcefire NGIPS) is released to customers.
    • Three different license levels
      • Personal
        • 29.99 a year/sensor
      • Business
        • 399.99 a year/sensor
      • Integrator
        • Integrate the Snort Subscriber Rule Set into your platform.
        • Your logo on our site as an authorized reseller
        • Our logo on your site and offerings
    • Published at least twice a week, Tuesdays and Thursdays
    • Contains the Community Ruleset
If you are familiar with the way our rule set was structured, you'll see some beneficial changes:
  • Our price for business Subscribers is now 399.99 a year/sensor.  This will make calculations easier.
  • Registered users now get updated content. If the rule was authored outside of the 30-day "new content" window, all users now receive updates to that content.  
  • In addition, we have renamed the rule set to "Snort Subscriber Rule Set".  Still developed by the same great team here at Cisco.
This should make things much simpler for everyone, and we hope you enjoy the content.

Introducing the new look of the Snort.org blog!

When we were redesigning Snort.org, we noticed the blog didn't match the design and colors we had established for the site.

So we decided to refresh the look of the Snort blog as well.  We hope you enjoy the new look and feel.  Thanks so much for supporting Snort!


Thursday, July 10, 2014

Snort Subscriber Rule Set Update for 07/10/2014

Just released:
Snort Subscriber Rule Set Update for 07/10/2014

We welcome the introduction of the newest rule release from the VRT. In this release we introduced 18 new rules and made modifications to 26 additional rules.

There were no changes made to the snort.conf in this release.


In VRT's rule release:
Synopsis: This release adds and modifies rules in several categories. 
Details: The Sourcefire VRT has added and modified multiple rules in the browser-firefox, browser-ie, browser-plugins, file-office, malware-backdoor, malware-cnc, os-windows, policy-other, pua-adware, server-apache and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

OpenAppID Training Videos: Integration with Splunk



In this video we will describe on how you can integrate the OpenAppID application statistics to work with Splunk's visualization tools.

Subscribe to the Snort OpenAppId Mailing list to participate in the discussion!

https://www.snort.org/community

Wednesday, July 9, 2014

The New Snort.org is here!

When the Cisco acquisition was announced, we created a list of things we wanted to accomplish right away, and right at the top of that list was a complete refresh of the outward facing platforms. The old snort.org was written in 2005. Except for moving to AWS several years ago, largely, it was the only major update to the system in those 9 years.

We wanted to design a snort.org that provided a next-level user and purchase experience as well as the ability to roll out new product offerings in the future and have one hub for all of it.

We’ve tried to make the user experience as optimal as possible, so I thought I’d run down a few housekeeping notes:

  • Layout
    • Much cleaner!  You’ll notice as you navigate around the site, a very simple layout.  We’ve moved most of the content from the old site over, so you should be able to find just about everything.  
    • All documentation for the rules is now available via the search field at the top left of every page.  Type in what you are looking for, hit enter.  No special syntax is needed for the GID and SID anymore, even though it’s still supported.
    • Almost everything on the site is accessible by two clicks.  There are some exceptions of course, but we tried to keep it as simple as possible.
  • User Management
    • We've eliminated the concept of a separate username apart from your email address. All usernames are now simply your email address.  If you do not know the email address assigned to your account, or if all you have is your oinkcode, you may contact us at snort-site@cisco.com and we'll help you out.
    • Passwords have been moved over from the old system intact. You can reset them at anytime.
    • Oinkcodes can now be reset.  If you accidentally post your Oinkcode on the mailing list or in a bug report, you can go in and click a button to regenerate it.
  • Purchasing Process
    • The whole process has been vastly simplified.
      • No longer do you have to move between pages to make a purchase, or receive a generic error.  You enter your credit card on the site, and it is stored as a token.  The actual credit card number is stored with our credit card vendor.  At no time does your credit card ever touch snort.org
      • The two tier pricing structure has been eliminated. No longer is there the "499$ for 1-5 sensors”. Our pricing structure is now 399$ for a business license across the board. 
      • Your card will be automatically charged annually for your purchase unless you cancel, this is new.  We've had this in the license for sometime, but the old website didn't have the capability.  You will receive two reminders of the expiration of your subscription.  30 days before expiration, and 7 days before.

New Features:

  • Rules
    • The “Snort Subscriber Rule Set”, has had three components for years.  Community, Registered, and Subscriber.  However, we’ve changed the way that the “Registered Rules” offering works.
    • Registered Rules
      • Up until now, the Registered Rule Set was 30 days behind.  This included new and updated content.  No longer!
      • Now, only new content isn’t included.  This means, if we make an update to an older rule, Registered Rule Subscribers get the new updates right away.  After 30 days the "new" content will be made available to Registered users as well.

  • PulledPork URLs
    • The URL structure for the rules is simpler.  We will still support the present/older format for about a year.  We can’t support the format forever, we still have people trying to download version 2.2 of the Snort ruleset once an hour, even though the ruleset hasn’t existed in almost 10 years!
  • All new “Get Started” Section
    • Choose your platform, Copy and paste the commands, done.




We are very enthusiastic about the new site and its future roadmap.  If you have suggestions, feedback, ideas or even compliments, please send them our way at snort-site@cisco.com and we'll take a look!

NOTE:  DNS will take a bit to update, so not everyone will see the site at the same time.  Be patient for us!

Tuesday, July 8, 2014

Snort Subscriber Rule Set Update for 07/08/2014

Just released:
Snort Subscriber Rule Set Update for 07/08/2014

We welcome the introduction of the newest rule release from the VRT. In this release we introduced 6 new rules and made modifications to 5 additional rules.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
Synopsis: The VRT is aware of vulnerabilities affecting products from Adobe Systems. 
Details: Adobe Security Bulletin APSB14-17: A coding deficiency exists in Adobe Flash Player that may lead to remote code execution. Rules to detect attacks targeting this vulnerability are included in this release and are identified with GID 1, SIDs 31392 through 31397.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Snort Subscriber Rule Set Update for 07/08/2014, MSTues

Just released:
Snort Subscriber Rule Set Update for 07/08/2014

We welcome the introduction of the newest rule release from the VRT. In this release we introduced 19 new rules and made modifications to 21 additional rules.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
Synopsis:
The Sourcefire VRT is aware of vulnerabilities affecting products from
Microsoft Corporation.

Details:
Microsoft Security Bulletin MS14-037:
Internet Explorer suffers from programming errors that may lead to
remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 31380 through 31391.

The Sourcefire VRT has also added and modified multiple rules in the
browser-ie, exploit-kit, file-multimedia, file-office, malware-tools
and server-webapp rule sets to provide coverage for emerging threats
from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

OpenAppID Training Videos: How to create a custom detector



In this video we will describe the process on how we have created a detector for VMWare's vSphere Console.

It demostrates the use of the client_registerPattern and matchSimplePattern API which are used to compare the raw packets of a specific TCP session.

Subscribe to the Snort OpenAppId Mailing list to participate in the discussion!

https://www.snort.org/community

Wednesday, July 2, 2014

Snort OpenAppID Detector Beta available!

We've released a new version of the OpenAppId content, and we wanted to share a few points about what we've added:

* Increased the coverage of our application detectors to an additional 800 detectors which brings our total coverage to 2,207 detectors. Some of those detectors include application based subclassifications such as "LinkedIn Upload", expanded coverage to protocol based detectors, different messaging platforms like the Kik Messenger and new torrent clients like uTorrent.

For more information about the list of detectors they can be viewed in the appMapping.data file.

* Improvements over the application detection that are based on SSL traffic

* Along with Snort 2.9.7.0 beta we have included the Open Source Detectors Developer Guide document which can be used for anyone that would like to write their own openappid detectors.

You can download Snort 2.9.7.0 beta and the OpenAppId content at https://www.snort.org/downloads in the Development section.

Tuesday, July 1, 2014

Snort Subscriber Rule Set Update for 07/01/2014

Just released:
Snort Subscriber Rule Set Update for 07/01/2014


We welcome the introduction of the newest rule release from the VRT. In this release we introduced 5 new rules and made modifications to 4 additional rules.

There were no changes made to the snort.conf in this release.

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Avery Tarasov:
31315


In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, browser-ie, browser-plugins, exploit, file-flash, malware-cnc and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!