What Does Suricata Do?

What Does Suricata Do?

Suricata is an open source network threat detection engine that provides capabilities including intrusion detection (IDS), intrusion prevention (IPS) and network security monitoring. It does extremely well with deep packet inspection and pattern matching which makes it incredibly useful for threat and attack detection.

How does Suricata work?

Suricata works by getting one packet at a time from the system. These are then pre-processed, after which they are passed to the detection engine. Suricata can use pcap for this in IDS mode, but can also connect to a special feature of Linux, named nfnetlink_queue. ... the packet is dropped using the 'drop' verdict.

What is Suricata and how do you use it?

What is Suricata used for?
  1. The simplest way is to set it up as a host-based IDS, which monitors the traffic of an individual computer.
  2. As a passive IDS, Suricata can monitor all of the traffic through a network and notify the administrator when it comes across anything malicious.
Maya Lin-Takahashi
Author

Maya Lin-Takahashi

Maya is a hardware enthusiast who tests and reviews smart home devices, smartphones, wearables, and audio gear. She focuses on practical consumer value and build quality.