Suricata 是一个网络入侵检测和阻止引擎,由开放信息安全基金会以及它所支持的提供商说开发。该引擎是多线程的,内置 IPv6 的支持,可加载预设规则,支持 Barnyard 和 Barnyard2 工具。

Suricata 1.4 发布首个 Beta 测试版本,主要改进包括:

添加AF_PACKET IPS模式支持.
添加自定义HTTP日志
添加TLS cert日志,存储,和指纹匹配
添加各种通道协议解码支持
NFQ fail-open support was added.
A rule option for limiting inspection to IPv4 or IPv6 was added.
The filesize keyword was added.
Delayed detection engine initialization support was added.
Various performance improvements were made 

[感谢open投递 via open资讯]

源链接

Hacking more

...