Skip to content

Commit 9bafcab

Browse files
committed
update changelog and docs
1 parent 1904e62 commit 9bafcab

File tree

2 files changed

+18
-2
lines changed

2 files changed

+18
-2
lines changed

CHANGELOG.md

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,18 @@
1-
- Add multiple telnet reconnection attempts detection
1+
2+
1.1.5 (Jan 3rd, 2025)
3+
- 200x times speedup of domain lookups in the threat intelligence module.
4+
- Add a threat level and confidence to each alert.
5+
- Add evidence for CN and hostname mismatch in SSL flows.
6+
- Add multiple telnet reconnection attempts detection.
7+
- Add support to IP ranges as the client_ip in slips.yaml
8+
- Alert "invalid DNS answer" on all private DNS answers.
9+
- Don't alert "high entropy TXT answers" for flows from multicast IPs.
10+
- Fix multiple reconnection attempts detection.
11+
- Fix problem downloading the latest MAC database from macvendors.com
12+
- Improve the detection of the Gateway IP and MAC when running on files and PCAPs.
13+
- Improve unit tests. Special thanks to @Sekhar-Kumar-Dash.
14+
- Split the "connection to/from blacklisted IPs" detection into two different evidence with different threat levels.
15+
- Update Slips internal list of Apple known ports.
216

317
1.1.4.1 (Dec 3rd, 2024)
418
- Fix abstract class starting with the rest of the modules.

docs/architecture.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,9 @@ This is what slips stores for each IP/Profile it creates:
8787

8888
### Alerts vs Evidence
8989

90-
When running Slips, the alerts you see in red in the CLI or at the very bottom in kalispo, are a bunch of evidence. Evidence in slips are detections caused by a specific IP in a specific timeframe. Slips doesn't alert on every evidence/detection. it accumulates evidence and only generates and alert when the amount of gathered evidence crosses a threshold. After this threshold Slips generates an alert, marks the timewindow as malicious(displays it in red in kalipso) and blocks the IP causing the alert.
90+
When running Slips, the alerts you see in red in the CLI or at the very bottom in kalispo, are a bunch of evidence. Evidence in slips are detections caused by a specific IP in a specific timeframe. Slips doesn't alert on every evidence/detection. it accumulates evidence and only generates and alert when the amount of gathered evidence crosses a threshold. After this threshold Slips generates an alert, marks the timewindow as malicious(displays it in red in kalipso and the web interface) and blocks the IP causing the alert if iptables is enabled.
91+
92+
Each alert has a threat level and confidence; the Threat level of each alert is Critical by default, and the confidence is the accumulated threat level of all the evidence of the alert normalized to a value ranging from 0 to 1. The more evidence the higher the confidence of the alert.
9193

9294
### Usage of Zeek.
9395

0 commit comments

Comments
 (0)