rules, rules, rules...

322 views
Skip to first unread message

Channing Jones

unread,
Nov 22, 2013, 6:05:47 PM11/22/13
to securit...@googlegroups.com
So far I have found that VRT distributes anonymous free GPL rules, registered user rules that are 30 days behind, and paid subscriber rules that are up-to-date and include the GPL rules. Also, ET has a free set that is the SO default choice, and they also have a paid subscriber set that includes some up-to-date malware-specific rules.

I'm interested in feedback on:

1) Why is the SO default the ET free set vs the GPL set from VRT? What is the difference?

2) Pro subscribers: why VRT/ why ET?

3) What are caveats and/or recommendations regarding combining rule sets?

Jeremy Hoel

unread,
Nov 22, 2013, 7:11:21 PM11/22/13
to securit...@googlegroups.com
We have at one time or another used all the rule sets above. Right
now we are paying for VRT registered rules. We do that because we have
SourceFire devices in addition to Snort so getting all the rules from
one place is great.

1) The Community/GPL rules are a small package, where the ET free/paid
set offer much more (in comparison to just the Community rule-set),
plus the community ruleset is a relatively new set.. and it might not
have been out when the SO project was setup.

2) Between VRT paid and ET paid, the VRT seemed to get more stable
rules, less FP; ET was newer threats, but at the cost of more FP.

3) Right now for our snort sensors we use VRT Paid, community and ET
free.. and it works fine, though when snort starts it complains about
duplicate rules from community and VRT Paid, but the Community ones
are newer and will be used.

Hope that helps..
> --
> You received this message because you are subscribed to the Google Groups "security-onion" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
> To post to this group, send email to securit...@googlegroups.com.
> Visit this group at http://groups.google.com/group/security-onion.
> For more options, visit https://groups.google.com/groups/opt_out.

Heine Lysemose

unread,
Nov 23, 2013, 1:13:38 AM11/23/13
to securit...@googlegroups.com

Hi

On Nov 23, 2013 1:11 AM, "Jeremy Hoel" <jth...@gmail.com> wrote:
>
> We have at one time or another used all the rule sets above.  Right
> now we are paying for VRT registered rules. We do that because we have
> SourceFire devices in addition to Snort so getting all the rules from
> one place is great.
>
> 1) The Community/GPL rules are a small package, where the ET free/paid
> set offer much more (in comparison to just the Community rule-set),
> plus the community ruleset is a relatively new set.. and it might not
> have been out when the SO project was setup.
>

The community ruleset is to be included in SecurityOnion when pulledpork is upgraded to version 0.7, https://code.google.com/p/security-onion/issues/detail?id=390.
The option to choose community ruleset was added/integrated in the 0.7 release.

> 2) Between VRT paid and ET paid, the VRT seemed to get more stable
> rules, less FP; ET was newer threats, but at the cost of more FP.
>
> 3) Right now for our snort sensors we use VRT Paid, community and ET
> free.. and it works fine, though when snort starts it complains about
> duplicate rules from community and VRT Paid, but the Community ones
> are newer and will be used.
>
> Hope that helps..
>

/Lysemose

Netavarka Suraksa

unread,
Dec 2, 2013, 11:47:06 PM12/2/13
to securit...@googlegroups.com

One caveat that I found when using combined freebie rule sets are the links to investigate what a rule means were less helpful in the ET rules. As a newbie to this arena when i clicked alink to the snort rule like "snort.org/search/sid/1-159" the limited documentation that comes from snorts rules homepage was helpful. But if the alert has come from ET and the link goes to snort.org/search/sid/100003456 then you see a not found page. The ET rules often have some links in them which offer description of the problem that prompted the rule like maybe a wikipedia page or some news article, but the link to the rule in the SO interfaces normally leads to the rule history page at ET. The rule history is not so inforrmative. Now I just use the ET set alone until I get to know all these tools better.

Could it be somewhere on the net that we can find or create a guide that documents what threw an alert on users lan? Such a forum might give have a clue what to investigate first. At this stage I spend as much time understanding what could be the meaning of the rule message as I do learning to even keep this onion running.

Joel Esler

unread,
Dec 4, 2013, 11:26:46 AM12/4/13
to securit...@googlegroups.com
If there are absolutely any ideas that you can throw me to help make things better.  I’m listening.

We are at a crucial stage right now and really can make some fantastic changes, so if there’s something that needs to be added or changed, please let me know.

--
Joel Esler
AEGIS Intelligence Lead
OpenSource Manager
Vulnerability Research Team, Sourcefire
Reply all
Reply to author
Forward
0 new messages