Training

Содержание сурикат в домашних условиях

Сурикаты хорошо адаптируются к жизни в неволе и легко приручаются; они жизнерадостны, активны, любопытны, игривы и ласковы, прямо как котята, и остаются таковыми до самой старости (а живут эти зверьки в неволе более 12 лет).  Эти качества делают сурикат очень привлекательными для содержания в домашних условиях. Но поскольку в природе эти зверьки привыкли жить большими семьями, лучше заводить не одного, а двух сурикат; если не хотите получать от них потомство – можно завести однополых

Вдвоем зверушкам никогда не будет скучно – всегда есть с кем поиграть и о ком заботиться – для сурикат это очень важно. Человек для суриката – друг, но все же семью заменить ему не может

Сурикат как домашний питомец

Сурикаты дружелюбны и общительны и как правило, хорошо уживаются другими домашними питомцами – кошками, хорьками и небольшими собаками. В какой то мере наличие в дома четвероногих даже может компенсировать недостаток внимания со стороны хозяина.

Сурикаты любят «поговорить» и издают более 30 звуков, которыми выражают различные эмоции, но при этом их нельзя назвать шумными животными.

Сурикаты не нуждаются в клетке. Их территория – вся квартира. Любопытный зверек любит свободно перемещаться по комнатам и наблюдать за тем, что происходит вокруг. При этом, как правило, они не портят мебель и вещи, не грызут провода. Питомцу понадобится только домик с подстилкой – здесь он будет спать. Поскольку в естественных условиях сурикаты живут в норах, домик подойдет удлиненной формы.

Некоторые владельцы для безопасности зверьков в свое отсутствие закрывают суриката в клетке. Клетка должна быть такой просторной, чтобы зверек мог спокойно хозяйничать, без стеснения движений. В клетке должно быть все необходимое – мягкая лежанка, миски с водой и едой, лоток.

К туалету суриката приучить будет посложнее, нежели котенка, но терпеливому хозяину это вполне по силам. В качестве туалета можно приспособить все тот же кошачий лоточек, только не забывайте почаще менять наполнитель.

Как уроженцы пустыни, зверьки не переносят холода и сквозняков, а любят солнце и тепло. У себя на родине сурикаты обожают принимать солнечные ванны. При содержании суриката дома у него тоже должна быть такая возможность. Летом проблем с солнечным светом, под лучами которого зверек мог бы понежиться, не возникает, – достаточно обеспечить ему доступ на один из подоконников на солнечной стороне. А вот зимой рекомендуется установить в подходящем месте Уф-лампу, чтобы и в это время года ваш питомец мог погреться под лучами хотя и искусственного, но все же солнца.

А еще сурикаты любят песочек. Порадуйте любимца – обустройте ему мини песочницу, где он будет с удовольствием проводить время.

Не забудьте и про игрушки. Сейчас в зоомагазинах богатый выбор игрушек для любых домашних питомцев – подберите своему любимцу что-нибудь шуршащее и пищащее.

Купание

Шерстка суриката пачкается, особенно если зверек гуляет на улице. Мыть питомцу лапки нужно после каждой прогулки. И не реже, чем раз в месяц, суриката нужно будет купать, используя мягкий зоошампунь. Делать это лучше в умывальнике под струей теплой воды. При этом необходимо следить за тем, чтобы вода не попала зверьку в уши, в противном случае последствия могут быть не самые приятные (возможно, даже придется обращаться к ветеринару). Пловцы из сурикат неважные, поэтому в свободное плаванье по тазику с водой их пускать нельзя. После водных процедур не отпускайте зверька бегать по квартире, сначала оботрите его полотенцем, а затем высушите феном.

Прогулки на свежем воздухе

В хорошую погоду с сурикатом можно выходить на прогулку. Это очень увлекательное мероприятие. Чтобы питомец не сбежал, выгуливать его нужно только на шлейке (подойдет шлейка для молодых хорьков). Гуляют с сурикатом только в теплое время года.

Необходимо иметь в виду, что гулять с сурикатом можно только после всех необходимых прививок (от чумы и бешенства). Сурикат вакцинируют также, как и хорьков.

Если сурикат гуляет на улице, а также если в вашем живут еще кошки или собаки, суриката следует обрабатывать от блох и клещей.

Где обитает сурикат?

Фото: Живой сурикат

Сурикаты распространены исключительно на юге Африки.

Их можно встретить в таких странах как:

  • ЮАР;
  • Зимбабве;
  • Намибия;
  • Ботсвана;
  • Замбия;
  • Ангола;
  • Конго.

Эти животные приспособлены к сухому жаркому климату, способны переносить пыльные бури. Поэтому они живут в пустынях и полупустынях. Например, сурикаты в большом количестве встречаются в районах пустыни Намиб и пустыни Калахари.

Хоть их и можно назвать выносливыми, но сурикаты совершенно не готовы к похолоданиям, и пониженную температуру они переносят тяжело. Об этом стоит помнить любителям завести дома экзотическое животное. В России стоит тщательно следить за домашним температурным режимам и исключать сквозняки для здоровья животного.

Сурикаты любят сухие более-менее рыхлые почвы, чтобы в них можно было вырыть убежище. Обычно оно имеет несколько входов и выходов и позволяет зверьку скрываться от врагов в один вход, и, пока хищник разрывает это место, сурикат удирает через другой выход. Также животные могут использовать чужие норы, вырытые другими животными и заброшенные. Или просто прятаться в природных почвенных выемках.

Если на местности преобладает каменистый фундамент, горы, обнажения, то сурикаты с радостью используют пещерки и закутки с той же целью, что и норы.

6.6.2. icode¶

With the icode keyword you can match on a specific ICMP code. The
code of a ICMP message clarifies the message. Together with the
ICMP-type it indicates with what kind of problem you are dealing with.
A code has a different purpose with every ICMP-type.

The format of the icode keyword:

icodemin<>max;
icode:[<|><number>;

Example:
This example looks for an ICMP code greater than 5:

icode>5;

Example of the icode keyword in a rule:

alert icmp $HOME_NET any -> $EXTERNAL_NET any (msg:”GPL MISC Time-To-Live Exceeded in Transit”; icode:0; itype:11; classtype:misc-activity; sid:2100449; rev:7;)

The following lists the meaning of all ICMP types. When a code is not listed,
only type 0 is defined and has the meaning of the ICMP code, in the table above.
A recent table can be found at the website of IANA

2.5. Alerting¶

To test the IDS functionality of Suricata it’s best to test with a signature. The signature with ID from the ET Open ruleset is written specific for such test cases.

2100498:

alert ip any any -> any any (msg"GPL ATTACK_RESPONSE id check returned root"; content"uid=0|28|root|29|"; classtypebad-unknown; sid2100498; rev7; metadatacreated_at 2010_09_23, updated_at 2010_09_23;)

The syntax and logic behind those signatures is covered in other chapters. This
will alert on any IP traffic that has the content within its payload. This rule
can be triggered quite easy. Before we trigger it, we will tail on the
so we see the result.

Ruletrigger:

sudo tail -f varlogsuricatafast.log
curl http//testmyids.com

The following output should now be seen in the log:

121004987 GPL ATTACK_RESPONSE id check returned root ** Classification Potentially Bad Traffic Priority 2 {TCP} 217.160.0.18780 -> 10.0.0.2341618

Социализация

Сурикаты – колониальные животные, их группы насчитывают от 15 до 30, реже до 45-63 особей. Каждая такая группа это настоящая семья, все члены которой связаны родственными узами. Во главе семьи всегда стоит самка, более мелкие самцы и самки занимают второстепенные роли, далее идут молодые животные и детеныши. Такой матриархат объясняется тем, что для поддержания рода этих мелких хищников важна плодовитость. Таким образом, самка, поставляющая клану детенышей, занимает привилегированное положение, остальные члены семьи обслуживают ее. Но это не значит, что главная самка подавляет других членов группы, она ведет такой же образ жизни как и все, просто младшие животные больше времени заняты обустройством нор.

Не считая редких конфликтов на границах участков сурикаты в целом отличаются очень кротким и дружелюбным нравом. Между членами семьи царит полное взаимопонимание и взаимовыручка. Молодые самцы и самки помогают старшей следить за подрастающими братишками и сестренками, когда она отлучается на поиски пищи; в холодную погоду сурикаты сбиваются в общую кучу и согревают друг друга; кроме того все члены семьи по очереди несут дежурство по «противововздушной обороне». Для этого сурикат взбирается на ветки кустарников или пологий ствол дерева и стоит на задних лапах, постоянно оглядываясь по сторонам. Увидев силуэт хищной птицы, он криком предупреждает остальных членов семьи об опасности и сам спешит укрыться в норе. По его знаку все прячутся и отсиживаются до тех пор, пока хищник не покинет территорию. Через несколько часов дежурный сменяется.

Войны за территорию

Территориальные конфликты летом, когда пища в избытке, происходят редко. Семьи могут кормиться на расстоянии нескольких десятков метров, не замечая, или игнорируя друг друга. При встречах в пограничной зоне группы ограничиваются ритуальными пограничными взаимодействиями.

С наступлением зимы корма становится все меньше, и семьи сурикат могут вторгаться на чужие территории. Когда часовые замечают чужаков, они издают громкий отрывистый звук, и все зверьки группы, задрав хвосты и взъерошив шерсть, «плечом к плечу» становятся на защиту территории. Через несколько минут противостояния одна из семей бросается в атаку. Каждая из групп чувствует себя увереннее на своей территории, и зачастую непрошенные гости сразу обращаются в бегство. Между равными по численности стабильными группами редко происходят кровопролитные сражения, но если семья за лето значительно выросла, она стремится расширить свою территорию. В таких случаях драки могут быть очень ожесточенными и даже оканчиваться гибелью части зверьков. Особенно самоотверженно сурикаты защищают свои норы с находящимися в них детёнышами, поскольку оставленные детёныши будут убиты чужаками.

Если во время влажного сезона образовалось несколько новых групп сурикат, то зимой неизбежно перераспределение территорий, которое будет сопровождаться жестокими схватками.

6.1.2. Protocol¶

drop tcp $HOME_NET any -> $EXTERNAL_NET any (msg:”ET TROJAN Likely Bot Nick in IRC (USA +..)”; flow:established,to_server; flowbits:isset,is_proto_irc; content:”NICK “; pcre:”/NICK .*USA.*{3,}/i”; reference:url,doc.emergingthreats.net/2008124; classtype:trojan-activity; sid:2008124; rev:2;)

This keyword in a signature tells Suricata which protocol it
concerns. You can choose between four basic protocols:

  • tcp (for tcp-traffic)
  • udp
  • icmp
  • ip (ip stands for ‘all’ or ‘any’)

There are also a few so-called application layer protocols, or layer 7 protocols
you can pick from. These are:

  • http
  • ftp
  • tls (this includes ssl)
  • smb
  • dns
  • dcerpc
  • ssh
  • smtp
  • imap
  • modbus (disabled by default)
  • dnp3 (disabled by default)
  • enip (disabled by default)
  • nfs (depends on rust availability)
  • ikev2 (depends on rust availability)
  • krb5 (depends on rust availability)
  • ntp (depends on rust availability)
  • dhcp (depends on rust availability)

The availability of these protocols depends on whether the protocol is enabled in the configuration file suricata.yaml.

Установка

Установку можно выполнить двумя способами:

  1. Из репозитория. Быстрый и удобный способ, но мы получим стандартную сборку без экзотических функций.
  2. Из исходников. Данный метод сложнее, но позволит собрать пакет с дополнительными опциями, например, CUDA для возможности использовать GPU.

Рассмотрим оба процесса.

Из репозитория

Устанавливаем репозиторий:

apt-get install software-properties-common

add-apt-repository ppa:oisf/suricata-stable

Когда увидим

Press to continue or ctrl-c to cancel adding it

… нажимаем Enter.

Обновляем список пакетов:

apt-get update

Устанавливаем suricata:

apt-get install suricata

Разрешаем автозапуск сервиса:

systemctl enable suricata

Из исходников

Рассмотрим пример установки пакета безопасности с поддержкой использования AF_PACKET. Процедуру разобьем на несколько этапов.

1. Подготовка к сборке

Устанавливаем необходимые для сборки пакеты:

apt-get install libpcre3 libpcre3-dbg libpcre3-dev build-essential autoconf automake libtool libpcap-dev libnet1-dev libyaml-0-2 libyaml-dev zlib1g zlib1g-dev libcap-ng-dev libcap-ng0 make libmagic-dev libjansson-dev libjansson4 pkg-config rustc cargo

Если необходимо использовать Suricata в качестве IPS, также ставим пакеты:

apt-get install libnetfilter-queue-dev libnetfilter-queue1 libnfnetlink-dev libnfnetlink0

Используя скопированную ссылку, скачиваем архив на сервер:

wget https://openinfosecfoundation.org/download/suricata-5.0.3.tar.gz

Распакуем его:

tar zxvf suricata-*.tar.gz

Переходим в каталог с распакованным архивом:

cd suricata-*

2. Сборка и установка

По умолчанию, suricata собирается как IDS. Рассмотрим оба варианта для конфигурирования.

а) если собираем для режима IDS:

./configure —prefix=/usr —sysconfdir=/etc —localstatedir=/var

б) если собираем для режима IPS:

./configure —enable-af-packet —prefix=/usr —sysconfdir=/etc —localstatedir=/var

* для возможности работы в режиме IPS необходимо включить опции —enable-af-packet или —enable-nfqueue.

После конфигурирования собираем пакет:

make

… и устанавливаем его:

make install

После установим конфигурационный файлы:

make install-conf

Для установки и обновления suricata ставим пакеты:

apt-get install python-pip

pip install —upgrade suricata-update

3. Завершение установки

Для полного завершения установки, создадим конфиг по умолчанию и сервис для автозапуска.

И так, создаем файл:

vi /etc/default/suricata

RUN=yes
RUN_AS_USER=
SURCONF=/etc/suricata/suricata.yaml
LISTENMODE=af-packet
IFACE=eth0
NFQUEUE=»-q 0″
CUSTOM_NFQUEUE=»-q 0 -q 1 -q 2 -q 3″
PIDFILE=/var/run/suricata.pid

Загружаем скрипт автозапуска командой:

wget https://www.dmosk.ru/files/suricata -P /etc/init.d

Разрешаем запуск файла:

chmod +x /etc/init.d/suricata

Перечитываем конфигурацию systemd:

systemctl daemon-reload

Разрешаем автозапуск suricata и стартуем ее сервис:

systemctl enable suricata

systemctl start suricata

6.7.12. byte_test¶

The keyword extracts and performs an operation selected with against the value in at a particular .

Format:

byte_test:<num of bytes>, <operator>, <test value>, <offset>  \
;
<num of bytes> The number of bytes selected from the packet to be converted
<operator>
  • Negation can prefix other operators
  • < less than
  • > greater than
  • = equal
  • <= less than or equal
  • >= greater than or equal
  • & bitwise AND
  • ^ bitwise OR
<value> Value to test the converted value against
<offset> Number of bytes into the payload
Offset relative to last content match
Type of number being read:
— big (Most significant byte at lowest address)
— little (Most significant byte at the highest address)
<num>
  • hex — Converted string represented in hex
  • dec — Converted string represented in dedimal
  • oct — Converted string represented in octal
Allow the DCE module determine the byte order
Applies the AND operator on the bytes converted

Example:

6.6.1. itype¶

The itype keyword is for matching on a specific ICMP type (number).
ICMP has several kinds of messages and uses codes to clarify those
messages. The different messages are distinct by different names, but
more important by numeric values. For more information see the table
with message-types and codes.

The format of the itype keyword:

itypemin<>max;
itype:[<|><number>;

Example
This example looks for an ICMP type greater than 10:

itype>10;

Example of the itype keyword in a signature:

alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:”GPL SCAN Broadscan Smurf Scanner”; dsize:4; icmp_id:0; icmp_seq:0; itype:8; classtype:attempted-recon; sid:2100478; rev:4;)

The following lists all ICMP types known at the time of writing. A recent table can be found at the website of IANA

6.1.3. Source and destination¶

drop tcp $HOME_NET any -> $EXTERNAL_NET any (msg:”ET TROJAN Likely Bot Nick in IRC (USA +..)”; flow:established,to_server; flowbits:isset,is_proto_irc; content:”NICK “; pcre:”/NICK .*USA.*{3,}/i”; reference:url,doc.emergingthreats.net/2008124; classtype:trojan-activity; sid:2008124; rev:2;)

The first emphasized part is the source, the second is the destination (note the direction of the directional arrow).

With source and destination, you specify the source of the traffic and the
destination of the traffic, respectively. You can assign IP addresses,
(both IPv4 and IPv6 are supported) and IP ranges. These can be combined with
operators:

Operator Description
IP ranges (CIDR notation)
! exception/negation
grouping

Normally, you would also make use of variables, such as and
. The configuration file specifies the IP addresses these
concern, and these settings will be used in place of the variables in you rules.
See for more information.

For example:

Example Meaning
! 1.1.1.1 Every IP address but 1.1.1.1
! Every IP address but 1.1.1.1 and 1.1.1.2
$HOME_NET Your setting of HOME_NET in yaml
EXTERNAL_NET and not HOME_NET
[10.0.0.0/24, !10.0.0.5] 10.0.0.0/24 except for 10.0.0.5
]  
]  

2.2. Basic setup¶

You should check on which interface Suricata should be running and also the
IP(s) of the interface:

ip a

2 enp1s0 <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
linkether 001122334455 brd ffffffffffff
inet 10.0.0.2324 brd 10.23.0.255 scope global noprefixroute enp1s0

Use that information to configure Suricata:

sudo vim etcsuricatasuricata.yaml

There will be a lot of possible configuration options, we focus on the setup of
the variable and the network interface configuration. The
variable should include, in most scenarios, the IP you have
configured on the interface you use to monitor and all the local networks in
use. The default already includes the RFC 1918 networks. In this example
is already included within . If no other networks
are used the other predefined can be removed.

In this example the interface name is so at the
section the interface name needs to match. An example interface config might
look like this:

Capture settings:

af-packet
    - interface enp1s0
      cluster-id 99
      cluster-type cluster_flow
      defrag yes
      use-mmap yes
      tpacket-v3 yes

6.7.1. content¶

The content keyword is very important in signatures. Between the
quotation marks you can write on what you would like the signature to
match. The most simple format of content is:

content "............";

It is possible to use several contents in a signature.

Contents match on bytes. There are 256 different values of a byte
(0-255). You can match on all characters; from a till z, upper case
and lower case and also on all special signs. But not all of the bytes
are printable characters. For these bytes heximal notations are
used. Many programming languages use 0x00 as a notation, where 0x
means it concerns a binary value, however the rule language uses
as a notation. This kind of notation can also be used for
printable characters.

Example:

|61| is a
|61 61| is aa
|41| is A
|21| is !
|0D| is carriage return
|0A| is line feed

There are characters you can not use in the content because they are
already important in the signature. For matching on these characters
you should use the heximal notation. These are:

"     |22|
;     |3B|
     |3A|
|     |7C|

It is a convention to write the heximal notation in upper case characters.

To write for instance in the content of a signature, you
should write it like this: If you use a
heximal notation in a signature, make sure you always place it between
pipes. Otherwise the notation will be taken literally as part of the
content.

A few examples:

content"a|0D|bc";
content"|61 0D 62 63|";
content"a|0D|b|63|";

It is possible to let a signature check the whole payload for a match with the content or to let it check specific parts of the payload. We come to that later.
If you add nothing special to the signature, it will try to find a match in all the bytes of the payload.

drop tcp $HOME_NET any -> $EXTERNAL_NET any (msg:”ET TROJAN Likely Bot Nick in IRC (USA +..)”; flow:established,to_server; flowbits:isset,is_proto_irc; content:”NICK “; pcre:”/NICK .*USA.*{3,}/i”; reference:url,doc.emergingthreats.net/2008124; classtype:trojan-activity; sid:2008124; rev:2;)

By default the pattern-matching is case sensitive. The content has to
be accurate, otherwise there will not be a match.

Legend:

It is possible to use the ! for exceptions in contents as well.

For example:

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"Outdated Firefox on
Windows"; content:"User-Agent|3A| Mozilla/5.0 |28|Windows|3B| ";
content:"Firefox/3."; distance:0; content:!"Firefox/3.6.13";
distance:-10; sid:9000000; rev:1;)

You see . This means an alert will be
generated if the used version of Firefox is not 3.6.13.

6.1.6. Rule options¶

The rest of the rule consists of options. These are enclosed by parenthesis
and separated by semicolons. Some options have settings (such as ),
which are specified by the keyword of the option, followed by a colon,
followed by the settings. Others have no settings, and are simply the
keyword (such as ):

<keyword> <settings>;
<keyword>;

Rule options have a specific ordering and changing their order would change the
meaning of the rule.

Note

The characters and have special meaning in the
Suricata rule language and must be escaped when used in a
rule option value. For example:

msg"Message with semicolon\;";

As a consequence, you must also escape the backslash, as it functions
as an escape character.

The rest of this chapter in the documentation documents the use of the various keywords.

Some generic details about keywords follow.

6.1.6.1. Modifier Keywords

Some keywords function act as modifiers. There are two types of modifiers.

  • The older style ‘content modifiers’ look back in the rule, e.g.:

    alert http any any -> any any (content"index.php"; http_uri; sid1;)
    

    In the above example the pattern ‘index.php’ is modified to inspect the HTTP uri buffer.

  • The more recent type is called the ‘sticky buffer’. It places the buffer name first and all keywords following it apply to that buffer, for instance:

    alert http any any -> any any (http_response_line; content"403 Forbidden"; sid1;)
    

    In the above example the pattern ‘403 Forbidden’ is inspected against the HTTP response line because it follows the keyword.

6.1.6.2. Normalized Buffers

A packet consists of raw data. HTTP and reassembly make a copy of
those kinds of packets data. They erase anomalous content, combine
packets etcetera. What remains is a called the ‘normalized buffer’:

Because the data is being normalized, it is not what it used to be; it
is an interpretation. Normalized buffers are: all HTTP-keywords,
reassembled streams, TLS-, SSL-, SSH-, FTP- and dcerpc-buffers.

Note that there are some exceptions, e.g. the keyword.
See for more information.

Перехват трафика и режимы работы

Чтобы определиться со способом установки suricata мы должны понимать принцип перехвата трафика. Есть несколько вариантов, как мы можем использовать программный продукт:

  • IDS — обнаружение вторжений.
  • IPS — предотвращение вторжений.
  • NSM — мониторинг безопасности.

Для организации IPS/IDS/NSM необходимо пропускать сетевой трафик через сервер suricata. Как правило, последний ставится на границе с Интернет. На основе правил и анализа система принимает решение, пропускать трафик или нет. В данном режиме под Linux есть два варианта фильтрации трафика — NFQUEUE и AF_PACKET. Первый работает медленнее, он использует встроенный сетефой фильтр операционной системы. Режим AF_PACKET требует нескольких интерфейсов, а система должна работать в качестве шлюза, при блокировки пакета он не будет передан на второй интерфейс.

При установке suricata из репозитория, работает режим NFQUEUE. Для возможности использования AF_PACKET необходима сборка из исходников.

Для настройки сурикаты в качестве IDS/NSM сервер не обязательно должен находиться на пути сетевого трафика — мы можем зеркалировать пакеты от сетевого оборудования в сторону сурикаты.

В данной инструкции мы рассмотрим пример настройки IDS/NSM с зеркалированием трафика от Mikrotik.

4.11.19. http_header_names¶

Inspect a buffer only containing the names of the HTTP headers. Useful
for making sure a header is not present or testing for a certain order
of headers.

Buffer starts with a \r\n and ends with an extra \r\n.

Example buffer:

\\r\\nHost\\r\\n\\r\\n

Example rule:

alert http any any -> any any (http_header_names; content"|0d 0a|Host|0d 0a|"; sid1;)

Example to make sure only Host is present:

alert http any any -> any any (http_header_names; \
        content"|0d 0a|Host|0d 0a 0d 0a|"; sid1;)

Example to make sure User-Agent is directly after Host:

alert http any any -> any any (http_header_names; \
        content"|0d 0a|Host|0d 0a|User-Agent|0d 0a|"; sid1;)

Example to make sure User-Agent is after Host, but not necessarily directly after:

6.3.8. fragoffset¶

With the fragoffset keyword you can match on specific decimal values
of the IP fragment offset field. If you would like to check the first
fragments of a session, you have to combine fragoffset 0 with the More
Fragment option. The fragmentation offset field is convenient for
reassembly. The id is used to determine which fragments belong to
which packet and the fragmentation offset field clarifies the order of
the fragments.

You can use the following modifiers:

<       match if the value is smaller than the specified value
>       match if the value is greater than the specified value
!       match if the specified value is not present

Format of fragoffset:

fragoffset:<number>;

Example of fragoffset in a rule:

4.2.1. msg (message)¶

The keyword msg gives textual information about the signature and the possible alert.

The format of msg is:

msg "some description";

Examples:

msg"ATTACK-RESPONSES 403 Forbidden";
msg"ET EXPLOIT SMB-DS DCERPC PnP bind attempt";

To continue the example of the previous chapter, this is the keyword in action in an actual rule:

drop tcp $HOME_NET any -> $EXTERNAL_NET any (msg:”ET TROJAN Likely Bot Nick in IRC (USA +..)”; flow:established,to_server; flowbits:isset,is_proto_irc; content:”NICK “; pcre:”/NICK .*USA.*{3,}/i”; reference:url,doc.emergingthreats.net/2008124; classtype:trojan-activity; sid:2008124; rev:2;)

Tip

It is convention to make the first part of the signature uppercase and show the class of the signature.

It is also convention that is made the first keyword in the signature.

4.6.10. rpc¶

The rpc keyword can be used to match in the SUNRPC CALL on the RPC
procedure numbers and the RPC version.

You can modify the keyword by using a wild-card, defined with * With
this wild-card you can match on all version and/or procedure numbers.

RPC (Remote Procedure Call) is an application that allows a computer
program to execute a procedure on another computer (or address
space). It is used for inter-process communication. See
http://en.wikipedia.org/wiki/Inter-process_communication

Format:

rpc<application number>, <version number>|*], <procedure number>|*>;

Example of the rpc keyword in a rule:

4.6.8. isdataat¶

The purpose of the isdataat keyword is to look if there is still data
at a specific part of the payload. The keyword starts with a number
(the position) and then optional followed by ‘relative’ separated by a
comma and the option rawbytes. You use the word ‘relative’ to know if
there is still data at a specific part of the payload relative to the
last match.

So you can use both examples:

isdataat512;

isdataat50, relative;

The first example illustrates a signature which searches for byte 512
of the payload. The second example illustrates a signature searching
for byte 50 after the last match.

You can also use the negation (!) before isdataat.

4.1.2. Protocol¶

drop tcp $HOME_NET any -> $EXTERNAL_NET any (msg:”ET TROJAN Likely Bot Nick in IRC (USA +..)”; flow:established,to_server; flowbits:isset,is_proto_irc; content:”NICK “; pcre:”/NICK .*USA.*{3,}/i”; reference:url,doc.emergingthreats.net/2008124; classtype:trojan-activity; sid:2008124; rev:2;)

This keyword in a signature tells Suricata which protocol it
concerns. You can choose between four basic protocols:

  • tcp (for tcp-traffic)
  • udp
  • icmp
  • ip (ip stands for ‘all’ or ‘any’)

There are also a few so-called application layer protocols, or layer 7 protocols
you can pick from. These are:

  • http
  • ftp
  • tls (this includes ssl)
  • smb
  • dns
  • dcerpc
  • ssh
  • smtp
  • imap
  • msn
  • modbus (disabled by default)
  • dnp3 (disabled by default)
  • enip (disabled by default)
  • nfs (depends on rust availability)
  • ikev2 (depends on rust availability)
  • krb5 (depends on rust availability)
  • ntp (depends on rust availability)
  • dhcp (depends on rust availability)

The availability of these protocols depends on whether the protocol is enabled in the configuration file suricata.yaml.

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *