Event language
UI language
Suricata is a world class Intrusion Detection and Prevention System known for its rich logging and super fast speed. Suricata is a FOSS project funded by the Open Information Security Foundation.<br>Suricata was founded in 2007 by Victor Julien and is going strong till date with the help of a small developer team and a worldwide community and consortium members.<br><br>This talk shall comprise of a small presentation about what Suricata is and what are the different ways it can be used followed by exercises on how one can run their own Suricata instance as an IDS, configure it and run it over their own network.<br><br>The talk layout would roughly be:<br><br>0. Introduction to the speaker [1 min]<br>1. Introduction to Suricata [2 mins]<br>2. What all Suricata can do [2 mins]<br>3. Modes that Suricata can operate under [1 mins]<br>4. Where to place Suricata within your network [1 min]<br>5. A demo of hands-on exercises using Suricata as an IDS [5 mins]<br> - [Exercise 1] Run Suricata with a given set of FOSS rules<br> - [Exercise 2] Write your own rule to get an alert<br> - [Exercise 3] Modify an existing rule to match the output expected<br>6. Q&A [3 mins]