Suricata

Suricata

Suricata (IDS/IPS/NSM)

Suricata is an open-source engine for the detection and prevention of network attacks (IDS/IPS) and for network monitoring (NSM). It checks network traffic rule-based for known threats, logs metadata and can report or block suspicious connections. It is a central building block of network-based security.

History & facts. Suricata is developed by the non-profit Open Information Security Foundation (OISF). It processes network traffic at high speed, detects threats based on rule sets, extracts protocol and metadata and, depending on the operating mode, can purely observe (IDS) or actively intervene (IPS). It thereby provides both alerts and rich data for network forensics.

Outlook & recommendation. Pure signature detection falls short against new attacks; its strength lies in the reliable detection of the known and in generating usable network telemetry. Combined with behaviour-based analysis and central evaluation, Suricata becomes an effective element of network observation (Network Detection and Response (NDR)/NSM) — precisely where no agent runs at the endpoint. As an open-source tool it fits into a sovereign, customisable security stack.

Suricata — Suricata