Suricata is a free, open source, mature, fast and powerful cyber threat detection engine.
The Suricata engine is capable of real-time intrusion detection (IDS), inline intrusion prevention (IPS), [network security] (https://cloud.tencent.com/product/ns?from=10680) monitoring (NSM) and offline pcap processing.
The core of many so-called enterprise security protection products is traffic detection based on suricata, which constantly compiles, updates and improves detection rules to improve security capabilities.
Environment: ubuntu1804
suricata version: 4.1.2
sudo apt-get install wget build-essential libpcre3-dev libpcre3-dbg automake autoconf libtool libpcap-dev libnet1-dev libyaml-dev zlib1g-dev libcap-ng-dev libjansson-dev pkg-config
wget https://www.openinfosecfoundation.org/download/suricata-4.1.2.tar.gz
tar -xvf suricata-4.1.2.tar.gz
cd suricata-4.1.2/
./configure --sysconfdir=/etc --localstatedir=/var
make
sudo make install
sudo mkdir /var/log/suricata
sudo mkdir /etc/suricata
sudo cp classification.config /etc/suricata
sudo cp reference.config /etc/suricata
sudo cp suricata.yaml /etc/suricata
sudo suricata -c /etc/suricata/suricata.yaml -i ens33
to start suricata: error while loading shared libraries: libhtp.so.2: cannot open shared object file: No such file or directory
Solution:
sudo vim /etc/ld.so.conf
/usr/local/lib
, saveldconfig
command to solveRecommended Posts