mirror of https://github.com/OISF/suricata
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
This commit adds support for the Remote Framebuffer Protocol (RFB) as used, for example, by various VNC implementations. It targets the official versions 3.3, 3.7 and 3.8 of the protocol and provides logging for the RFB handshake communication for now. Logged events include endpoint versions, details of the security (i.e. authentication) exchange as well as metadata about the image transfer parameters. Detection is enabled using keywords for: - rfb.name: Session name as sticky buffer - rfb.sectype: Security type, e.g. VNC-style challenge-response - rfb.secresult: Result of the security exchange, e.g. OK, FAIL, ... The latter could be used, for example, to detect brute-force attempts on open VNC servers, while the name could be used to map unwanted VNC sessions to the desktop owners or machines. We also ship example EVE-JSON output and keyword docs as part of the Sphinx source for Suricata's RTD documentation. |
6 years ago | |
|---|---|---|
| .. | ||
| 3rd-party-integration | 7 years ago | |
| _static | 8 years ago | |
| capture-hardware | 6 years ago | |
| configuration | 6 years ago | |
| file-extraction | 6 years ago | |
| licenses | 7 years ago | |
| lua | 7 years ago | |
| manpages | 7 years ago | |
| output | 6 years ago | |
| partials | 6 years ago | |
| performance | 6 years ago | |
| reputation | 6 years ago | |
| rule-management | 6 years ago | |
| rules | 6 years ago | |
| setting-up-ipsinline-for-linux | ||
| .gitignore | ||
| Makefile.am | 6 years ago | |
| Makefile.sphinx | ||
| README.md | 6 years ago | |
| acknowledgements.rst | 8 years ago | |
| command-line-options.rst | 9 years ago | |
| conf.py | 6 years ago | |
| convert.py | ||
| index.rst | 6 years ago | |
| initscripts.rst | ||
| install.rst | 6 years ago | |
| make-sense-alerts.rst | 8 years ago | |
| public-data-sets.rst | 8 years ago | |
| quickstart.rst | 6 years ago | |
| setting-up-ipsinline-for-linux.rst | 6 years ago | |
| setting-up-ipsinline-for-windows.rst | 8 years ago | |
| unix-socket.rst | 6 years ago | |
| upgrade.rst | 6 years ago | |
| what-is-suricata.rst | 9 years ago | |
README.md
Suricata User Guide
This directory contains the Suricata Guide. The Sphinx Document Generator is used to build the documentation. For a primer os reStructuredText see the reStructuredText Primer.
Verifying Changes
There are a number of output formats to choose from when making the source documentation locally (e.g. html, pdf, man).
The documentation source can be built with make -f Makefile.sphinx html. Substitute the 'html' word for desired output format.
There are different application dependencies based on the output desired.