Changes for version 0.09 - 2012-04-30
- changed snort output so that the 'protocol' field is set to tcp/udp/icmp/ip according to the value in the CIF database (previously 'ip' was always outputted)
- added to config file (~/.cif) variable default
- snort_classtype null (won't appear in the outputted rules) snort_tag null (won't appear in the outputted rules) snort_priority default based on CIF severity (5=medium, 9=high otherwise 1) snort_threshold "type limit,track by_src,count 1,seconds 3600" snort_srcnet any snort_srcport any
- example ~/.cif excerpt
- snort_startsid = 1234567000 snort_classtype = botnet-connection-known snort_tag = "session, 50, packets" snort_priority = 1 snort_sourcenet = "[$HOME_NET,!$TRUSTED]"
Modules
Perl extension that extends REST::Client for use with the CI-Framework REST interface
Provides
in lib/CIF/Client/Plugin/Bindzone.pm
in lib/CIF/Client/Plugin/Csv.pm
in lib/CIF/Client/Plugin/Html.pm
in lib/CIF/Client/Plugin/Iodef.pm
in lib/CIF/Client/Plugin/Iodef/Bgp.pm
in lib/CIF/Client/Plugin/Iodef/Domain.pm
in lib/CIF/Client/Plugin/Iodef/Email.pm
in lib/CIF/Client/Plugin/Iodef/Group.pm
in lib/CIF/Client/Plugin/Iodef/Ipv4.pm
in lib/CIF/Client/Plugin/Iodef/Malware.pm
in lib/CIF/Client/Plugin/Iodef/Service.pm
in lib/CIF/Client/Plugin/Iodef/ShareWith.pm
in lib/CIF/Client/Plugin/Iodef/Url.pm
in lib/CIF/Client/Plugin/Iptables.pm
in lib/CIF/Client/Plugin/Output.pm
in lib/CIF/Client/Plugin/Parser.pm
in lib/CIF/Client/Plugin/Pcapfilter.pm
in lib/CIF/Client/Plugin/Raw.pm
in lib/CIF/Client/Plugin/Snort.pm
in lib/CIF/Client/Plugin/Table.pm