Custom Snort 3 Intrusion Policies for Access Control

PDF

Custom Snort 3 Intrusion Policies for Access Control

Examples for migration

Want to summarize with AI?

Log in

Describes Snort 2 to Snort 3 migration scenarios and examples.



Migrate from Snort 2 to Snort 3

Migrating from Snort 2 to Snort 3

  • involves converting and adapting the Snort 2 rules to the Snort 3 rule syntax,

  • optimizes the rules for improved detection and performance, and

  • allows organizations to leverage the enhanced features and capabilities of Snort 3.

Organizations with Threat Defense devices managed by the Secure Firewall Management Center can opt for a hybrid deployment approach during the migration from Snort 2 to Snort 3. This approach allows for a gradual transition and minimizes potential disruptions, if any.


Benefits of migrating to snort 3

Snort 3 provides

  • Enhanced protocol support: Snort 3 provides improved protocol support, allowing you to detect and monitor threats across a wide range of modern protocols, including encrypted traffic.

  • Streamlined rule management: Snort 3 offers a more user-friendly rule language and rule management system, making it easier to create, modify, and manage rules effectively.

  • Improved performance: Snort 3 has been optimized to handle higher traffic volumes more efficiently, ensuring timely threat detection and reducing the risk of performance bottlenecks.


Sample business scenario

This sample business scenario is an illustrative situation that

  • demonstrates how organizations evaluate network security inspection engine migrations,

  • shows the roles and motivations of security analysts and network administrators in technology decisions, and

  • highlights the benefits of upgrading from legacy to modern security monitoring solutions.

Organizational migration scenario

Alice works as a security analyst in a large organization that heavily relies on the Snort inspection engine to monitor and protect their network infrastructure. The organization has been using Snort Version 2 for several years, but they have encountered some limitations and challenges.

Bob, the network administrator, is looking to migrate from Snort 2 to Snort 3 to overcome these issues and enhance his organization's network security capabilities.

This migration will also improve network security monitoring, enhance performance, and streamline rule management.


Best practices for migrating from Snort 2 to Snort 3

Follow these best practices when migrating from Snort 2 to Snort 3 to ensure data integrity and maintain security coverage.


Prerequisites for migration

Complete these prerequisites before starting the migration process to ensure system readiness and data protection.


End-to-end migration workflow


Enable Snort 3 on Threat Defense device

Enable Snort 3 on your Threat Defense device for enhanced security capabilities.

Use this procedure to upgrade from Snort 2 to Snort 3 on your Threat Defense device.

During the deployment process, there could be a momentary traffic loss because the current inspection engine needs to be shut down.

Procedure

1.

Choose Devices > Device Management.

2.

Click the corresponding device to go to the device home page.

3.

Click the Device tab.

4.

In the Inspection Engine section, click Upgrade.

The image illustrates the deployment process of converting policy configurations to ensure compatibility with the selected Snort version in a threat defense system.
5.

Click Yes.

What to do next

Deploy the changes on the device. See Deploy configuration changes.

The system converts your policy configurations during the deployment process to make them compatible with the selected Snort version.


Convert Snort 2 rules of a single intrusion policy to Snort 3

This task synchronizes and converts Snort 2 intrusion policy rules to Snort 3 format, ensuring that custom rules, thresholds, and suppressions are properly migrated to maintain security policy effectiveness when using Snort 3 engines.

When intrusion policies display an orange arrow indicator, the Snort 2 and Snort 3 versions are not synchronized. The synchronization process uses the snort2Lua tool to convert rules and may require manual intervention for custom rules, thresholds, and suppressions that cannot be automatically migrated.

Before you begin

Follow these steps to convert Snort 2 rules of a single intrusion policy to Snort 3:

Procedure

1.

Choose Policies > Access Control heading > Intrusion > Intrusion Policies.

  1. In the Intrusion Policies tab, click Show Snort 3 Sync status.

    The image illustrates the synchronization status of Snort 2 and Snort 3 intrusion policies, highlighting an orange arrow that indicates a mismatch between the two versions.

    If your policy displays an orange arrow, it indicates that the Snort 2 and the Snort 3 versions of the intrusion policy are not synchronized.

    The Snort 2 to Snort 3 Sync Summary page shows an orange arrow indicating that the Snort 2 and Snort 3 versions of the intrusion policy are not synchronized, with the sync status marked as pending.
  2. Click the orange arrow.

    The Snort 2 to Snort 3 Sync Summary page displays that the Snort 2 to Snort 3 sync is pending.

    The Snort 2 to Snort 3 Sync Summary page shows the status of the sync process, indicating that the conversion of rules from Snort 2 to Snort 3 is currently pending.
  3. Click Re-Sync to start the synchronization.

    Note
    When you click Re-Sync, the snort2Lua tool converts the rules from Snort 2 to Snort 3.

    The Summary Details section lists the rules that were migrated or skipped. In our use case, there are 76 custom Snort 2 rules, 17 rules with thresholds, and 15 rules with suppression that were skipped during the sync process. To migrate the custom rules, go to the next step.

    The snort2Lua tool interface displays the conversion process from Snort 2 rules to Snort 3, highlighting the number of rules migrated, skipped, and their respective categories.

    To migrate rules with thresholds and suppressions, go to Step 6.

    The Summary Details section shows the migration status of Snort 2 rules, indicating which rules were migrated, skipped, or had thresholds and suppressions during the sync process.
2.

To migrate the 76 custom rules, perform either one of these steps:

  • In the Custom Rules tab, click the Import icon to convert and auto-import the local rules to the Snort 3 version of the policy.

    The Custom Rules tab in Snort 3 shows the Import icon used to convert and auto-import local Snort 2 rules, with a confirmation message indicating successful import.

    A confirmation message is displayed after the rules are successfully imported.

  • Choose Objects > Intrusion Rules and click Snort 3 All Rules.

    1. Click Local Rules in the left panel to check if any rules have been migrated. Notice that no custom rules from Snort 2 have been migrated.

    2. From the Tasks drop-down list, choose Convert Snort 2 rules and import.

      The image illustrates the process of converting Snort 2 rules to Snort 3, highlighting the steps to check for migrated rules and initiate the conversion.
    3. Click OK.

      A rule group named (All Snort 2 Converted Global) is now created under Local Rules in the left panel.

      Notice that all 76 custom rules have been migrated, as shown in the following figure.

      The figure displays a summary of the converted Snort 2 rules, highlighting the successful migration of 76 custom rules into the newly created rule group under Local Rules.

    Alternatively, you can select the Convert Snort 2 rules and download in the previous step to save the rules file locally. You can review the converted rules in the downloaded file and later upload them using the Upload Snort 3 rules option.

3.

Click the Download Summary Details link to download the rules in .txt format.

This is a sample of the summary that is displayed.

Example:

  "id": "00505691-15DC-0ed3-0000-004294988561",
  "name": "_Intrusion_Policy_1",
  "type": "IntrusionPolicy",
  "syncStatus": {
    "source": {
      "id": "bdce2d6a-1ebe-11ee-8e88-220032eb1fb5",
      "type": "IntrusionPolicy"
    },
    "status": "WARN",
    "description": "Migration is partially successful. Some of the rules are not copied to Snort3.",
    "timestamp": 1690883954814,
    "lastUser": {
      "name": "admin"
    },
    "details": [
      {
        "type": "Summary",
        "status": "INFO",
        "description": "Based on Talos rule-mapping 18639 Snort 2 rule action overrides migrated to 18635 Snort 3 rules."
      },
      {
        "id": "1:1000156=alert,1:1000114=alert,1:1000160=alert,1:1000135=alert,1:1000115=alert,1:1000118=alert,
         1:1000092=alert,1:1000139=alert,1:1000123=alert,1:1000159=alert,1:1000149=disabled,1:1000167=alert,
         1:1000133=alert,1:1000095=alert,1:1000143=alert,1:1000106=alert,1:1000153=alert,1:1000097=alert,1:1000141=alert,
         1:1000148=alert,1:1000090=alert,1:1000119=alert,1:1000112=alert,1:1000138=alert,1:1000128=alert,1:1000132=alert,
         1:1000134=alert,1:1000145=disabled,1:1000110=disabled,1:1000107=alert,1:1000163=alert,1:1000124=alert,1:1000125=alert,
         1:1000094=alert,1:1000113=disabled,1:1000147=alert,1:1000161=alert,1:1000105=disabled,1:1000140=alert,1:1000111=alert,
         1:1000102=alert,1:1000129=disabled,1:1000108=alert,1:1000144=disabled,1:1000088=alert,1:1000091=alert,1:1000131=alert,
         1:1000157=alert,1:1000120=alert,1:1000126=alert,1:1000165=alert,1:1000146=alert,1:1000162=alert,1:1000116=alert,1:1000142=alert,
         1:1000170=disabled,1:1000169=alert,1:1000104=alert,1:1000099=disabled,1:1000171=alert,1:1000093=alert,1:1000087=alert,1:1000100=alert,
         1:1000137=alert,1:1000158=alert,1:1000103=alert,1:1000098=alert,1:1000127=disabled,1:1000130=alert,1:1000164=alert,1:1000089=alert,
         1:1000109=alert,1:1000136=alert,1:1000117=alert,1:1000166=alert,1:1000168=alert",
        "type": "PolicyInfo",
        "description": "Corresponding Snort 2 policy overridden custom (local) rules."
      },
      {
        "type": "AssignedDevices",
        "status": "INFO",
        "description": "Snort3:0 , Snort2:0"
      },
      {
        "id": "122:6",
        "type": "Threshold",
        "status": "ERROR",
        "description": "PSNG_TCP_FILTERED_DECOY_PORTSCAN"
      },
      {
        "id": "122:15",
        "type": "Threshold",
        "status": "ERROR",
        "description": "PSNG_IP_PORTSWEEP_FILTERED"
       },
      {
        "id": "122:1",
        "type": "Threshold",
        "status": "ERROR",
        "description": "PSNG_TCP_PORTSCAN"
      },
4.

Click Close to close the Sync Summary dialog box.

5.

To check the rules with status: ERROR, choose Policies > Access Control heading > Intrusion and click the Snort 2 version of the intrusion policy.

6.

Under Policy Information, click Rules and filter for the rule. For example, enter PSNG_TCP_PORTSCAN in the Filterfield to find the rule.

7.

Click Show Details to view the detailed version of the rule.

8.

Create the rule again in Snort 3 using Snort 3 rule guidelines and save the file as a .txt or .rules file. For more information, see www.snort3.org.

9.

Upload the custom rule that you just created locally to the list of all the Snort 3 rules. See Add Custom Rules to Rule Groups.

What to do next

Deploy configuration changes. See Deploy configuration changes.