Back to tutorials
Key takeaways
- Suricata installs cleanly on Ubuntu from the official OISF PPA:
sudo add-apt-repository ppa:oisf/suricata-stablethensudo apt-get install -y suricata, which avoids the frozen versions shipped in distro repos. - The critical part of
/etc/suricata/suricata.yamlis two sections:varsto declareHOME_NET(your internal ranges) andEXTERNAL_NET: "!$HOME_NET", andaf-packetfor the monitoring interface (threads: auto,cluster-type: cluster_flow,use-mmap: yes). It is YAML: bad indentation breaks everything. - Rules are managed with
sudo suricata-update, which pulls the ET Open ruleset by default;suricata-update list-sourceslists the other sources you can enable. Schedule it in cron, followed bysystemctl reload suricata. - Always validate before starting with
sudo suricata -T -c /etc/suricata/suricata.yaml -v: the-Tflag checks the config and the rules. Then test for real:curl -A "BlackSun" http://SURICATA_IPfires the "ET MALWARE BlackSun" rule that is enabled by default. - IPS mode (active blocking) requires putting Suricata inline via NFQUEUE:
sudo iptables -I FORWARD -j NFQUEUEthensuricata -c /etc/suricata/suricata.yaml -q 0. Get it wrong and you cut all network traffic — and the real work is still tuning rules to kill false positives.
What is Suricata?
Suricata is an open-source, high-performance and mature network threat detection engine. It can act as an Intrusion Detection System (IDS), an Intrusion Prevention System (IPS), and a Network Security Monitoring (NSM) tool. It was designed to be multi-threaded, which allows it to take full advantage of modern multi-core processors.
Suricata is an open-source, high-performance and mature network threat detection engine. It can act as an Intrusion Detection System (IDS), an Intrusion Prevention System (IPS), and a Network Security Monitoring (NSM) tool. It was designed to be multi-threaded, which allows it to take full advantage of modern multi-core processors.
Why use Suricata?
- High Performance: Designed for multi-threading, it can inspect network traffic at very high bandwidth.
- Advanced Detection: It can not only use signature-based rules (like Snort), but also analyze protocols and extract files for deeper analysis.
- Modern Ecosystem: Logs are output in EVE JSON format, a structured format that is easy to integrate with tools like an ELK stack (Elasticsearch, Logstash, Kibana) or Splunk.
- Simple rule management: It includes a tool, `suricata-update`, to make updating rule sets easier.
Prerequisites
- A Linux server (Ubuntu/Debian is used in this guide).
- Root access or sudo privileges.
- A network interface dedicated to listening to traffic (monitoring).
Premium Content
This advanced tutorial is reserved for premium members.
9,90€ / month
- All advanced tutorials
- New content every week
- Progress tracking
- Cancel anytime