[Oisf-devel] [Oisf-users] new Suricata master requires libhtp update

Brant Wells bwells at tfc.edu
Wed Feb 3 04:36:13 UTC 2010


Hey Victor,

Breno & I have dome some basic stress testing with his code, and I have to say that Suricata held up pretty well to the testing.  Work has been a real pain this week, and I haven't had time to test anything other than "hot topic" projects that I have on my plate (no shortage of those, either!), but I will try to get the new codebase on Monday and maybe get it going in Inline mode and see if I can document steps that someone else can reproduce.

Cheerio!
~Brant

On Feb 2, 2010, at 7:48 PM, Breno Silva wrote:

I will do that Victor,

I think our first goal is stress the algorithm/concept running it in many different kind of networks. The community will be very very important during this stage.

After some weeks of test ... if we (devel team and community) decide it is really good engine for all or almost all kind of networks and to detect a good range of threats as a complement of pattern match engine... i will spend more time doing more robust code (we have a lot of tasks to do :-) )

I will port the code to the current master this weekend

cheers

Breno



On Tue, Feb 2, 2010 at 7:39 AM, Victor Julien <victor at inliniac.net<mailto:victor at inliniac.net>> wrote:
Hi Breno, I think it would be useful to rebase your code to the current
master. In any case I will require that before doing a review :)

Cheers,
Victor

Breno Silva wrote:
> Try to download the suricata beta version and apply the patch i sent in
> the list.
>
> Let me know if you have any problem
>
>
> thanks
>
> Breno
>
>
> On Mon, Feb 1, 2010 at 4:39 PM, Brant Wells <bwells at tfc.edu<mailto:bwells at tfc.edu>
> <mailto:bwells at tfc.edu<mailto:bwells at tfc.edu>>> wrote:
>
>     Okay.  You emailed me a patch against the version you were working
>     on the other night.  I haven’t had a chance to test it.  Should I
>     test it against the master branch or continue to use the branch that
>     you have been operating off of?
>
>
>
>     Thanks!
>     ~Brant
>
>
>
>
>
>     *From:* Breno Silva [mailto:breno.silva at gmail.com<mailto:breno.silva at gmail.com>
>     <mailto:breno.silva at gmail.com<mailto:breno.silva at gmail.com>>]
>     *Sent:* Monday, February 01, 2010 1:34 PM
>     *To:* Brant Wells
>     *Cc:* oisf-users at openinfosecfoundation.org<mailto:oisf-users at openinfosecfoundation.org>
>     <mailto:oisf-users at openinfosecfoundation.org<mailto:oisf-users at openinfosecfoundation.org>>;
>     oisf-devel at openinfosecfoundation.org<mailto:oisf-devel at openinfosecfoundation.org>
>     <mailto:oisf-devel at openinfosecfoundation.org<mailto:oisf-devel at openinfosecfoundation.org>>; Victor Julien
>     *Subject:* Re: [Oisf-devel] [Oisf-users] new Suricata master
>     requires libhtp update
>
>
>
>     Hi Brant,
>
>
>
>     My patch need some changes to be part of master code. However we
>     have a good start to test the idea/algorithm. I think the community
>     can help us in this task.
>
>
>
>     We can think about CUDA for the entropy operations in the feature too.
>
>
>
>
>
>     thanks
>
>
>
>     Breno
>
>     On Mon, Feb 1, 2010 at 12:53 PM, Victor Julien <victor at inliniac.net<mailto:victor at inliniac.net>
>     <mailto:victor at inliniac.net<mailto:victor at inliniac.net>>> wrote:
>
>     Hi Brant,
>
>     It's still in my review queue, so hopefully soon.
>
>     Cheers,
>     Victor
>
>
>     Brant Wells wrote:
>     > Hey Victor,
>     >
>     > Does this new master include the Entropy changes that Breno has
>     been working on?
>     >
>     > Thanks!
>     > ~Brant
>     >
>     >
>     > -----Original Message-----
>     > From: oisf-users-bounces at openinfosecfoundation.org<mailto:oisf-users-bounces at openinfosecfoundation.org>
>     <mailto:oisf-users-bounces at openinfosecfoundation.org<mailto:oisf-users-bounces at openinfosecfoundation.org>>
>     [mailto:oisf-users-bounces at openinfosecfoundation.org<mailto:oisf-users-bounces at openinfosecfoundation.org>
>     <mailto:oisf-users-bounces at openinfosecfoundation.org<mailto:oisf-users-bounces at openinfosecfoundation.org>>] On Behalf Of
>     Victor Julien
>     > Sent: Monday, February 01, 2010 5:22 AM
>     > To: oisf-users at openinfosecfoundation.org<mailto:oisf-users at openinfosecfoundation.org>
>     <mailto:oisf-users at openinfosecfoundation.org<mailto:oisf-users at openinfosecfoundation.org>>;
>     oisf-devel at openinfosecfoundation.org<mailto:oisf-devel at openinfosecfoundation.org>
>     <mailto:oisf-devel at openinfosecfoundation.org<mailto:oisf-devel at openinfosecfoundation.org>>
>     > Subject: [Oisf-users] new Suricata master requires libhtp update
>     >
>     > Hi everyone,
>     >
>     > I just pushed out a new Suricata master. It contains improved
>     uricontent
>     > code that requires you to update your libhtp. We're going to include
>     > libhtp in our own code base for convenience soon, until then get
>     it here:
>     >
>     > svn co
>     https://libhtp.svn.sourceforge.net/svnroot/libhtp/branches/0.2.x
>     >
>     > Cheers,
>     > Victor
>     >
>     >
>
>
>     --
>     ---------------------------------------------
>     Victor Julien
>     http://www.inliniac.net/
>     PGP: http://www.inliniac.net/victorjulien.asc
>     ---------------------------------------------
>
>     _______________________________________________
>
>     Oisf-devel mailing list
>     Oisf-devel at openinfosecfoundation.org<mailto:Oisf-devel at openinfosecfoundation.org>
>     <mailto:Oisf-devel at openinfosecfoundation.org<mailto:Oisf-devel at openinfosecfoundation.org>>
>     http://lists.openinfosecfoundation.org/mailman/listinfo/oisf-devel
>
>
>
>


--
---------------------------------------------
Victor Julien
http://www.inliniac.net/
PGP: http://www.inliniac.net/victorjulien.asc
---------------------------------------------



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-devel/attachments/20100202/bb02b73e/attachment-0002.html>


More information about the Oisf-devel mailing list