Suricata, Emerging Threats and the OISF take on Sourcefire and Snort
There has been much made recently over the introduction of another open source IDS engine into the market. It is called Suricata and it is funded by the Open Information Security Foundation (OISF). The OISF is itself funded partially by government grants by the DHS and others. If you are not a security aficionado, this may not be interesting to you. You may not already know of Snort, the de facto standard in intrusion detection and one of the most successful open source projects in security at the least. But if you are into security, another open source IDS alternative is big news.
In addition to an entirely new IDS engine, the same driving force behind the OISF, Matt Jonkman has also started Emerging Threats Pro. For years Emerging Threats and its predecessors published an alternative open source rule set for Snort and other IDS engines that support the Snort syntax. Of course Sourcefire sells their VRT ruleset for Snort as well. Now Jonkman and Emerging Threats Pro are offering their own alternative “for pay” rule set to compete head on with Sourcefire and the VRT ruleset.
I recently had a chance to sit down with Matt, whom I have known for many years as a result of my own involvement in the open source IDS community. Below is our conversation. It is about 26 minutes long and chocked full of open source IDS information.
It should be noted that I invited and tried to have a Sourcefire representative appear in our podcast. But scheduling everyone became too big of a chore and after much wasted time, I did this with just Matt. Maybe I will have Sourcefire on a later episode.
While Matt’s Suricata IDS is another entrant in the IDS market. Matt doesn’t necessarily think of it as a Snort killer or Snort replacement. It is just another angle on doing IDS. An angle that Matt believes is better suited to todays network and threat environments.
Suricata uses a different rule format than Snort. The VRT rule set would not suit Suricata, so Matt had to have an alternative rule set. His idea is if you have a rule set, why not make it also work with Snort, which is the de facto standard anyway. This certainly puts him in a head to head competition with Sourcefire.
In the meantime it will be interesting to see if there is enough room for two open source IDS engines to thrive in the market. God knows there are enough threats out there, but only time will tell.




