Exciting.<br>I am looking forward to some samples/examples.<br><br><div class="gmail_quote">On Thu, Nov 29, 2012 at 5:02 PM, Anoop Saldanha <span dir="ltr"><<a href="mailto:anoopsaldanha@gmail.com" target="_blank">anoopsaldanha@gmail.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Probably including the et_pro list in your cc can get you folks<br>
feedback on the keywords side of things.<br>
<div class="HOEnZb"><div class="h5"><br>
On Thu, Nov 29, 2012 at 9:25 PM, Daniel Wyschogrod <<a href="mailto:dwyschogrod@bbn.com">dwyschogrod@bbn.com</a>> wrote:<br>
> Our current plan is to add detectors and introduce new keywords for the ICMP work.<br>
><br>
> Dan<br>
> ____________________<br>
> Dan Wyschogrod<br>
><br>
> Senior Scientist<br>
> Cyber Security<br>
> Raytheon/BBN Technologies<br>
><br>
> <a href="mailto:dwyschogrod@bbn.com">dwyschogrod@bbn.com</a><br>
><br>
><br>
><br>
><br>
> On Nov 29, 2012, at 9:59 AM, Victor Julien <<a href="mailto:victor@inliniac.net">victor@inliniac.net</a>> wrote:<br>
><br>
>> On 11/29/2012 03:49 PM, Ron Watro wrote:<br>
>>> At BBN we are working on some “ protocol shepherds” that we’d like to<br>
>>> contribute to Suricata.  Our idea is to build a set of rules that focus<br>
>>> on a specific protocol and that detect the common attacks and/or misuses<br>
>>> of the protocol.   We are starting with ICMP (we did note that there<br>
>>> were some existing rules here) and after that will move to DNS and<br>
>>> others.   Dan Wyschogrod and David Mandelberg are the key developers on<br>
>>> the project.  We’ve got the OISF developer agreement and have sent that<br>
>>> to our legal department for approval.  We’ll be posting more info and<br>
>>> asking questions about Suricata shortly.   Looking forward to helping<br>
>>> make Suricata an even bigger success.  –Ron Watro<br>
>><br>
>> Sounds interesting. Will these be purely done using the existing rule<br>
>> language, or will rule language extensions be necessary?<br>
>><br>
>> --<br>
>> ---------------------------------------------<br>
>> Victor Julien<br>
>> <a href="http://www.inliniac.net/" target="_blank">http://www.inliniac.net/</a><br>
>> PGP: <a href="http://www.inliniac.net/victorjulien.asc" target="_blank">http://www.inliniac.net/victorjulien.asc</a><br>
>> ---------------------------------------------<br>
>><br>
>> _______________________________________________<br>
>> Suricata IDS Devel mailing list: <a href="mailto:oisf-devel@openinfosecfoundation.org">oisf-devel@openinfosecfoundation.org</a><br>
>> Site: <a href="http://suricata-ids.org" target="_blank">http://suricata-ids.org</a> | Participate: <a href="http://suricata-ids.org/participate/" target="_blank">http://suricata-ids.org/participate/</a><br>
>> List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-devel" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-devel</a><br>
>> Redmine: <a href="https://redmine.openinfosecfoundation.org/" target="_blank">https://redmine.openinfosecfoundation.org/</a><br>
><br>
><br>
> _______________________________________________<br>
> Suricata IDS Devel mailing list: <a href="mailto:oisf-devel@openinfosecfoundation.org">oisf-devel@openinfosecfoundation.org</a><br>
> Site: <a href="http://suricata-ids.org" target="_blank">http://suricata-ids.org</a> | Participate: <a href="http://suricata-ids.org/participate/" target="_blank">http://suricata-ids.org/participate/</a><br>
> List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-devel" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-devel</a><br>
> Redmine: <a href="https://redmine.openinfosecfoundation.org/" target="_blank">https://redmine.openinfosecfoundation.org/</a><br>
<br>
<br>
<br>
</div></div><span class="HOEnZb"><font color="#888888">--<br>
Anoop Saldanha<br>
</font></span><div class="HOEnZb"><div class="h5">_______________________________________________<br>
Suricata IDS Devel mailing list: <a href="mailto:oisf-devel@openinfosecfoundation.org">oisf-devel@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" target="_blank">http://suricata-ids.org</a> | Participate: <a href="http://suricata-ids.org/participate/" target="_blank">http://suricata-ids.org/participate/</a><br>
List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-devel" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-devel</a><br>
Redmine: <a href="https://redmine.openinfosecfoundation.org/" target="_blank">https://redmine.openinfosecfoundation.org/</a></div></div></blockquote></div><br><br clear="all"><br>-- <br><div>Regards,</div>
<div>Peter Manev</div><br>