SNORT3
Snortは、IPネットワーク上でリアルタイムのトラフィック分析とパケットロギングを実行できるオープンソースのネットワーク侵入検知システムです。
「プロトコル分析」「コンテンツ検索」「マッチング」を実行でき、「バッファオーバーフロー」「ステルスポートスキャン」「CGI攻撃」「SMBプローブ」「OSフィンガープリント試行」「セマンティックURL攻撃」「サーバメッセージブロック探査」など、さまざまな攻撃検出に使用できます。
1.事前準備
1.1 必須パッケージのインストール
1.openssl-develのインストール
# dnf -y install openssl-devel
2.cmakeのインストール
# dnf -y install cmake
1.2 必要なパッケージのインストール
# dnf -y install libpcap-devel pcre-devel libdnet-devel hwloc-devel openssl-devel zlib-devel luajit-devel pkgconf libmnl-devel libunwind-devel
# dnf -y install libnfnetlink-devel libnetfilter_queue g++
1.3 LibDAQのインストール
# dnf install git
# git clone https://github.com/snort3/libdaq.git
Cloning into 'libdaq'...
remote: Enumerating objects: 2691, done.
remote: Counting objects: 100% (313/313), done.
remote: Compressing objects: 100% (125/125), done.
remote: Total 2691 (delta 240), reused 212 (delta 188), pack-reused 2378 (from 2)
Receiving objects: 100% (2691/2691), 1.26 MiB | 13.42 MiB/s, done.
Resolving deltas: 100% (1932/1932), done.
# cd libdaq/
# dnf -y install autoconf
# ./bootstrap
# ./configure
# make && make install
# ln -s /usr/local/lib/libdaq.so.3 /lib/
共有ライブラリの追加
# ldconfig
ライブラリの確認
# ldconfig -p|grep daq
libdaq.so.3 (libc6,x86-64) => /lib/libdaq.so.3
1.4 オプションパッケージのインストール
1.LZMAとUUIDのインストール
# dnf -y install xz-devel libuuid-devel
2.Hyperscanのインストール
# dnf -y install hyperscan hyperscan-devel
3.Tcmallocのインストール
# dnf -y install gperftools-devel
2. Snort3のインストール
不足パッケージインストール
# dnf -y install pcre2-devel
# dnf -y install flex
# git clone https://github.com/snort3/snort3.git
# cd snort3/
# export PKG_CONFIG_PATH=/usr/local/lib/pkgconfig:$PKG_CONFIG_PATH
# export PKG_CONFIG_PATH=/usr/local/lib64/pkgconfig:$PKG_CONFIG_PATH
# export CFLAGS="-O3"
# export CXXFLAGS="-O3 -fno-rtti"
# ./configure_cmake.sh --prefix=/usr/local/snort --enable-tcmalloc
# cd build/
# pwd
/root/snort3/build
# make -j$(nproc)
# make -j$(nproc) install
バージョン確認
# /usr/local/snort/bin/snort -V
,,_ -*> Snort++ <*-
o" )~ Version 3.12.2.0
'''' By Martin Roesch & The Snort Team
http://snort.org/contact#team
Copyright (C) 2014-2026 Cisco and/or its affiliates. All rights reserved.
Copyright (C) 1998-2013 Sourcefire, Inc., et al.
Using DAQ version 3.0.27
Using Hyperscan version 5.4.1 2023-04-14
Using libpcap version 1.10.0 (with TPACKET_V3)
Using LuaJIT version 2.1.0-beta3
Using LZMA version 5.2.5
Using OpenSSL 3.5.5 27 Jan 2026
Using PCRE2 version 10.40 2022-04-14
Using ZLIB version 1.2.11
テスト実行
# /usr/local/snort/bin/snort -c /usr/local/snort/etc/snort/snort.lua
--------------------------------------------------
pcap DAQ configured to passive.
Snort successfully validated the configuration (with 0 warnings).
o")~ Snort exiting
ネットワークインターフェースの設定
ネットワーク インタフェースを確認
# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 00:0c:29:ba:7a:22 brd ff:ff:ff:ff:ff:ff
altname enp3s0
inet 192.168.11.83/24 brd 192.168.11.255 scope global noprefixroute ens160
valid_lft forever preferred_lft forever
inet6 fe80::20c:29ff:feba:7a22/64 scope link noprefixroute
valid_lft forever preferred_lft forever
ネットワーク・インターフェース名はens160である
ネットワークインターフェイスをプロミスキャスモードに設定する。こうすることで、ネットワークデバイスはすべてのネットワークパケットをキャプチャし、検査できるようになる。
# ip link set dev ens160 promisc on
設定を確認
# ip a | grep ens160 | grep mtu
2: ens160: <BROADCAST,MULTICAST,PROMISC,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
ネットワーク・インタフェースのオフロード・ステータスを確認。インタフェースのネッ トワーク・トラフィックを監視する必要がある場合は、オフロードを無効にする必要がある
# ethtool -k ens160 | grep receive-offload
generic-receive-offload: on
large-receive-offload: on
onになっているので下記コマンドでGRO,LROを無効にする
# ethtool -K ens160 gro off lro off
再度状況を確認する
# ethtool -k ens160 | grep receive-offload
generic-receive-offload: off
large-receive-offload: off
Snortネットワークインターフェース用のsystemdサービスを作成する
# vi /etc/systemd/system/snort3-nic.service
[Unit]
Description=Set Snort 3 NIC in promiscuous mode and Disable GRO, LRO on boot
After=network.target
[Service]
Type=oneshot
ExecStart=/usr/sbin/ip link set dev ens160 promisc on
ExecStart=/usr/sbin/ethtool -K ens160 gro off lro off
TimeoutStartSec=0
RemainAfterExit=yes
[Install]
WantedBy=default.target
systemd デーモン変更を適用する
# systemctl daemon-reload
# systemctl enable snort3-nic.service
Created symlink /etc/systemd/system/default.target.wants/snort3-nic.service → /etc/systemd/system/snort3-nic.service.
# systemctl start snort3-nic.service
Snortコミュニティ・ルールセットを追加
1.Snortルール用のフォルダを作成し、SnortのWebサイトからコミュニティルールセットをダウンロードし、所定のルールディレクトリーに配置
# mkdir /usr/local/snort/etc/snort/rules
# wget -qO- https://www.snort.org/downloads/community/snort3-community-rules.tar.gz | tar xz -C /usr/local/snort/etc/snort/rules/
2.Snortメイン設定ファイルを編集
# vi /usr/local/snort/etc/snort/snort.lua
●24行目変更
HOME_NET = '192.168.11.0/24'
●28行目変更
EXTERNAL_NET = '!$HOME_NET'
●188行目当たりのips項目の最後に追加
ips =
{
-- use this to enable decoder and inspector alerts
-- enable_builtin_rules = true,
-- use include for rules files; be sure to set your path
-- note that rules files can include other rules files
-- (see also related path vars at the top of snort_defaults.lua)
variables = default_variables,
rules = [[
include /usr/local/snort/etc/snort/rules/snort3-community-rules/snort3-community.rules
]]
}
3.Snortのメインコンフィグレーションの変更をテスト
# /usr/local/snort/bin/snort -c /usr/local/snort/etc/snort/snort.lua
--------------------------------------------------
pcap DAQ configured to passive.
Snort successfully validated the configuration (with 0 warnings).
o")~ Snort exiting
カスタムルールの追加
1.Snort rulesディレクトリにファイルを作成する
# vi /usr/local/snort/etc/snort/rules/local.rules
alert icmp any any -> $HOME_NET any (msg:"Incoming ICMP"; sid:1000001; rev:1;)
2.Snortメイン設定ファイルを編集
カスタム ルール ファイル ディレクトリをメイン構成に含めるためSnortメイン設定ファイルを編集
# vi /usr/local/snort/etc/snort/snort.lua
●199行目当たりに追加
ips =
{
-- use this to enable decoder and inspector alerts
--enable_builtin_rules = true,
-- use include for rules files; be sure to set your path
-- note that rules files can include other rules files
-- (see also related path vars at the top of snort_defaults.lua)
variables = default_variables,
rules = [[
include /usr/local/snort/etc/snort/rules/local.rules
include /usr/local/snort/etc/snort/rules/snort3-community-rules/snort3-community.rules
]]
}
3.Snortのメインコンフィグレーションの変更をテスト
# /usr/local/snort/bin/snort -c /usr/local/snort/etc/snort/snort.lua
--------------------------------------------------
pcap DAQ configured to passive.
Snort successfully validated the configuration (with 0 warnings).
o")~ Snort exiting
OpenAppIDエクステンションをインストール
OpenAppIDエクステンションをインストールすると、Snortはアプリケーションレイヤーレベルでネットワーク脅威を検出できるようになります
1.OpenAppIDエクステンションダウンロードと展開
# wget https://www.snort.org/downloads/openappid/33380 -O OpenAppId-33380.tgz
# tar -xzvf OpenAppId-33380.tgz
2.解凍したフォルダ(odp)を以下のディレクトリにコピー
# cp -R odp /usr/local/lib/
3.Snortメイン設定ファイルを編集し、OpenAppIDフォルダの場所を定義
# vi /usr/local/snort/etc/snort/snort.lua
●99行目当たりのappidセクションに追加
appid =
{
-- appid requires this to use appids in rules
--app_detector_dir = 'directory to load appid detectors from'
app_detector_dir = '/usr/local/lib',
log_stats = true,
}
appid_listener =
{
json_logging = true,
file = "/var/log/snort/appid-output.log",
}
--[[
reputation =
4.Snortのメインコンフィグレーションの変更をテスト
# /usr/local/snort/bin/snort -c /usr/local/snort/etc/snort/snort.lua
--------------------------------------------------
pcap DAQ configured to passive.
Snort successfully validated the configuration (with 0 warnings).
o")~ Snort exiting
すべてのコンフィギュレーションが正しくセットアップされていることを確認する
# /usr/local/snort/bin/snort -c /usr/local/snort/etc/snort/snort.lua -R /usr/local/snort/etc/snort/rules/local.rules -i ens160 -A alert_fast -s 65535 -k none
リモートコンピュータからサーバのIPアドレスにpingコマンドを送信します。これにより、ホストサーバーのコンソールウィンドウに下記のようなアラートログが表示されます
--------------------------------------------------
pcap DAQ configured to passive.
Commencing packet processing
Retry queue interval is: 200 ms
++ [0] ens160
08/21-13:41:17.646126 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.14 -> 192.168.11.83
08/21-13:41:17.646126 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.14 -> 192.168.11.83
08/21-13:41:17.646412 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.83 -> 192.168.11.14
08/21-13:41:18.654516 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.14 -> 192.168.11.83
08/21-13:41:18.654516 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.14 -> 192.168.11.83
08/21-13:41:18.654836 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.83 -> 192.168.11.14
08/21-13:41:18.654922 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.83 -> 192.168.11.14
08/21-13:41:19.667490 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.14 -> 192.168.11.83
08/21-13:41:19.667490 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.14 -> 192.168.11.83
08/21-13:41:19.667679 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.83 -> 192.168.11.14
08/21-13:41:19.667781 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.83 -> 192.168.11.14
08/21-13:41:20.671521 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.14 -> 192.168.11.83
08/21-13:41:20.671522 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.14 -> 192.168.11.83
08/21-13:41:20.671693 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.83 -> 192.168.11.14
08/21-13:41:20.671792 [**] [1:1000001:1] "Incoming ICMP" [**] [Priority: 0] [AppID: ICMP] {ICMP} 192.168.11.83 -> 192.168.11.14
Snort systemdサービスの設定
1.Snortサービス用のユーザの作成
# useradd -r -s /usr/sbin/nologin -M snort
2.ログフォルダの作成とパーミッションの設定
Snortログ用のディレクトリフォルダを作成し、フォルダパーミッションを設定
# mkdir /var/log/snort
# chmod -R 5775 /var/log/snort
# chown -R snort:snort /var/log/snort
3.Systemdサービスファイルの作成
# vi /etc/systemd/system/snort3.service
[Unit]
Description=Snort3 IDS Daemon Service
After=syslog.target network.target
[Service]
Type=simple
ExecStart=/usr/local/snort/bin/snort -c /usr/local/snort/etc/snort/snort.lua -s 65535 -k none -l /var/log/snort -D -i ens160 -m 0x1b -u snort -g snort
ExecStop=/bin/kill -9 $MAINPID
[Install]
WantedBy=multi-user.target
Snortサービスをリロードして有効にする
# systemctl daemon-reload
# systemctl enable --now snort3.service
Snortサービスを開始
# systemctl start snort3.service
Snort IDS ロギング
1.Snort JSONロギングの設定
# vi /usr/local/snort/etc/snort/snort.lua
●262行目当たりの-- 7. configure outputsセクションの最後にalert_jsonを追加
-------------------------------------------------------------------------------------
-- 7. configure outputs
-------------------------------------------------------------------------------------
-- event logging
-- you can enable with defaults from the command line with -A <alert_type>
-- uncomment below to set non-default configs
--alert_csv = { }
--alert_fast = { }
--alert_full = { }
--alert_sfsocket = { }
--alert_syslog = { }
--unified2 = { }
-- packet logging
-- you can enable with defaults from the command line with -L <log_type>
--log_codecs = { }
--log_hext = { }
--log_pcap = { }
-- additional logs
--packet_capture = { }
--file_log = { }
alert_json =
{
file = true,
limit = 50,
fields = 'timestamp msg pkt_num proto pkt_gen pkt_len dir src_addr src_port dst_addr dst_port service rule priority class action b64_data'
}
2.Snortを再起動
# systemctl restart snort3.service
3.ログファイルを確認
リモートコンピュータからサーバにpingコマンドを実行する。Snort alert_json.txtファイルに保存されます。
# tail -f /var/log/snort/alert_json.txt
{ "timestamp" : "08/21-13:47:49.487838", "msg" : "Incoming ICMP", "pkt_num" : 868, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "S2C", "src_addr" : "192.168.11.83", "dst_addr" : "192.168.11.14", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
{ "timestamp" : "08/21-13:47:49.488344", "msg" : "Incoming ICMP", "pkt_num" : 869, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "S2C", "src_addr" : "192.168.11.83", "dst_addr" : "192.168.11.14", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
{ "timestamp" : "08/21-13:47:50.497453", "msg" : "Incoming ICMP", "pkt_num" : 871, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "C2S", "src_addr" : "192.168.11.14", "dst_addr" : "192.168.11.83", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
{ "timestamp" : "08/21-13:47:50.497453", "msg" : "Incoming ICMP", "pkt_num" : 872, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "C2S", "src_addr" : "192.168.11.14", "dst_addr" : "192.168.11.83", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
{ "timestamp" : "08/21-13:47:50.497698", "msg" : "Incoming ICMP", "pkt_num" : 873, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "S2C", "src_addr" : "192.168.11.83", "dst_addr" : "192.168.11.14", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
{ "timestamp" : "08/21-13:47:50.497835", "msg" : "Incoming ICMP", "pkt_num" : 874, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "S2C", "src_addr" : "192.168.11.83", "dst_addr" : "192.168.11.14", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
{ "timestamp" : "08/21-13:47:51.509644", "msg" : "Incoming ICMP", "pkt_num" : 952, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "C2S", "src_addr" : "192.168.11.14", "dst_addr" : "192.168.11.83", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
{ "timestamp" : "08/21-13:47:51.509644", "msg" : "Incoming ICMP", "pkt_num" : 953, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "C2S", "src_addr" : "192.168.11.14", "dst_addr" : "192.168.11.83", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
{ "timestamp" : "08/21-13:47:51.509903", "msg" : "Incoming ICMP", "pkt_num" : 954, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "S2C", "src_addr" : "192.168.11.83", "dst_addr" : "192.168.11.14", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
{ "timestamp" : "08/21-13:47:51.510032", "msg" : "Incoming ICMP", "pkt_num" : 955, "proto" : "ICMP", "pkt_gen" : "raw", "pkt_len" : 60, "dir" : "S2C", "src_addr" : "192.168.11.83", "dst_addr" : "192.168.11.14", "service" : "unknown", "rule" : "1:1000001:1", "priority" : 0, "class" : "none", "action" : "allow", "b64_data" : "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dndhYmNkZWZnaGk=" }
以上でSnort 3のインストールと設定が完了
ルールファイルの自動更新
Snort が不正アクセスの判断をするために参照するルールファイルを自動で最新化するoinkmaster をインストールする
1. Oinkmasterインストール
# wget http://prdownloads.sourceforge.net/oinkmaster/oinkmaster-2.0.tar.gz
# tar zxvf oinkmaster-2.0.tar.gz
下記ファイルを所定のディレクトリへコピー
# cp oinkmaster-2.0/oinkmaster.pl /usr/local/bin/
# cp oinkmaster-2.0/oinkmaster.conf /etc/
# cp oinkmaster-2.0/oinkmaster.1 /usr/share/man/man1/
下記ファイル、ディレクトリーを削除
# rm -rf oinkmaster-2.0
# rm -f oinkmaster-2.0.tar.gz
2. Oink Codeの取得
Snortルールファイル(Sourcefire VRT Certified Rules)をダウンロードするには「Oink Code」が必要なので、「Oink Code」を取得する。
まず、SNORT公式ページにアクセスしユーザー登録を行い、登録したアカウント、パスワードでSign in後"Oinkcode"を表示し、コピーする。
3. Oinkmaster設定
Oinkmaster設定ファイルを編集
取得したOinkcodeを貼り付ける
# vi /etc/oinkmaster.conf
56行目当たり : 下記を追加
<file_name>の箇所にはSNORTにサインイン後、使用しているSNORTバージョンに一致する最新のsnortrules-snapshot-xxxxx.tar.gzを貼り付ける
<oinkcode>の箇所に取得したoinkcodeを貼り付ける
url = http://www.snort.org/pub-bin/oinkmaster.cgi/<oinkcode>/<file_name>
4. ダウンロードする(Oinkmaster実行)
# oinkmaster.pl -o /usr/local/snort/etc/snort/rules/
下記のように表示される
Loading /etc/oinkmaster.conf
Downloading file from http://www.snort.org/pub-bin/oinkmaster.cgi/*oinkcode*/snortrules-snapshot-31200.tar.gz... done.
Archive successfully downloaded, unpacking... done.
Setting up rules structures... done.
Processing downloaded rules... disabled 0, enabled 0, modified 0, total=47682
Setting up rules structures... done.
Comparing new files to the old ones... done.
Updating local rules files... done.
[***] Results from Oinkmaster started 20260821 15:06:13 [***]
[*] Rules modifications: [*]
None.
[*] Non-rule line modifications: [*]
None.
[+] Added files (consider updating your snort.conf to include them if needed): [+]
-> includes.rules
-> snort3-app-detect.rules
-> snort3-browser-chrome.rules
-> snort3-browser-firefox.rules
-> snort3-browser-ie.rules
-> snort3-browser-other.rules
-> snort3-browser-plugins.rules
-> snort3-browser-webkit.rules
-> snort3-content-replace.rules
-> snort3-exploit-kit.rules
-> snort3-file-executable.rules
-> snort3-file-flash.rules
-> snort3-file-identify.rules
-> snort3-file-image.rules
-> snort3-file-java.rules
-> snort3-file-multimedia.rules
-> snort3-file-office.rules
-> snort3-file-other.rules
-> snort3-file-pdf.rules
-> snort3-indicator-compromise.rules
-> snort3-indicator-obfuscation.rules
-> snort3-indicator-scan.rules
-> snort3-indicator-shellcode.rules
-> snort3-malware-backdoor.rules
-> snort3-malware-cnc.rules
-> snort3-malware-other.rules
-> snort3-malware-tools.rules
-> snort3-netbios.rules
-> snort3-os-linux.rules
-> snort3-os-mobile.rules
-> snort3-os-other.rules
-> snort3-os-solaris.rules
-> snort3-os-windows.rules
-> snort3-policy-multimedia.rules
-> snort3-policy-other.rules
-> snort3-policy-social.rules
-> snort3-policy-spam.rules
-> snort3-protocol-dns.rules
-> snort3-protocol-finger.rules
-> snort3-protocol-ftp.rules
-> snort3-protocol-icmp.rules
-> snort3-protocol-imap.rules
-> snort3-protocol-nntp.rules
-> snort3-protocol-other.rules
-> snort3-protocol-pop.rules
-> snort3-protocol-rpc.rules
-> snort3-protocol-scada.rules
-> snort3-protocol-services.rules
-> snort3-protocol-snmp.rules
-> snort3-protocol-telnet.rules
-> snort3-protocol-tftp.rules
-> snort3-protocol-voip.rules
-> snort3-pua-adware.rules
-> snort3-pua-other.rules
-> snort3-pua-p2p.rules
-> snort3-pua-toolbars.rules
-> snort3-server-apache.rules
-> snort3-server-iis.rules
-> snort3-server-mail.rules
-> snort3-server-mssql.rules
-> snort3-server-mysql.rules
-> snort3-server-oracle.rules
-> snort3-server-other.rules
-> snort3-server-samba.rules
-> snort3-server-webapp.rules
-> snort3-sql.rules
-> snort3-x11.rules
-> VRT-License.txt
5. Oinkmaster定期自動実行設定
Oinkmaster定期自動実行スクリプト作成
# vi /etc/cron.daily/snort-rule-update
下記内容を記述
#!/bin/bash
/usr/local/bin/oinkmaster.pl -o /usr/local/snort/etc/snort/rules/ 2>&1 | logger -t oinkmaster
systemctl restart snort3 > /dev/null
スクリプトに実行権限
# chmod +x /etc/cron.daily/snort-rule-update
