[LWN Logo]
[LWN.net]
From:	 Martin Roesch <roesch@sourcefire.com>
To:	 snort-announce <snort-announce@lists.sourceforge.net>,
	 snort-dev <snort-devel@lists.sourceforge.net>,
	 snort-users <snort-users@lists.sourceforge.net>,
	 focus-ids <focus-ids@securityfocus.com>,
	 Bugtraq <BUGTRAQ@securityfocus.com>, ids@uow.edu.au, lwn@lwn.net
Subject: Snort 1.8 released
Date:	 Mon, 09 Jul 2001 23:52:27 -0400

In a dress-rehearsal for the impending arrival of his baby later this
month, Martin Roesch has finally squeezed out Snort version 1.8.  

Snort 1.8 is available at:

http://www.snort.org/files/snort-1.8-RELEASE.tar.gz

Version 1.8 incorporates a number of changes and new features, including
some of the following:

New things:
* Stateful inspection and TCP stream reassembly module
* High performance IP defragmenter module
* High performance unified binary output module
* Tagging allows hosts that trip events to be tracked/logged
* Unique Rule IDs for every Snort rule and new printout code make
machine processing of Snort output much easier
* Enhanced cross-reference data with alerts
* Classifications and Priorities added to rules language
* ARP spoofing detection
* "IP" is now a supported protocol type in the Snort rules language
* Back Orifice detection plugin
* Telnet normalization plugin defeats telnet and ftp evasion techniques
* RPC normalization plugin defeats RPC fragmentation evasion techniques
* CSV format output plugin
* "uricontent" keyword allows HTTP traffic to be searched for data in
the URI field only
* 802.1Q decoder support
* linux_sll decoder support
* tcp window detection plugin
* same IP detection plugin
* -T switch to test Snort config before running
* -y switch to add year to timestamps
* -I switch to print interface name in Snort alerts
* -G switch for backawards compatability with old cross-reference lookup
progs
* -L switch for naming the -b binary output file
* -k switch to tune checksum verification routines
* -z switch to run the rules engine in stateful mode (with stream4)

Additionally, there were a ton of fixes and development in the rest of
the code, and the spo_xml and spo_database routines have matured over
the past 6 months as well.

The full Changelog can be seen at http://www.snort.org/Changelog.htm for
the changes since 1.7 was released last January.

I'd like to thank Fyodor Yarochkin, Brian Caswell, Phil Wood, Jed
Pickel, Roman Danyliw, Dragos Ruiu, Jim Forster, Max Vision, the Silicon
Defense gang, Chris Cramer, Eugene Tsyrklevich, Chris Green, HD Moore,
DrSuse, Jeff Nathan and the whole gang on #snort for helping to make it
happen.  

Happy Snorting!

     -Marty

--
Martin Roesch
roesch@sourcefire.com
http://www.sourcefire.com - http://www.snort.org