Suricata for Debian ------------------- The engine is an Open Source Next Generation Intrusion Detection and Prevention Tool, not intended to just replace or emulate the existing tools in the industry, but to bring new ideas and technologies to the field. To run the engine with default configuration on a network interface (in live mode), run the following command (as root), replacing with an interface of this system: suricata -c /etc/suricata/suricata.yaml -i To run in live NFQUEUE mode, use (as root): suricata -c /etc/suricata/suricata.yaml -q $QUEUE_ID You can also run suricata on a PCAP file: suricata -c /etc/suricata/suricata.yaml -r file.pcap Landlock LSM security sandbox ----------------------------- Suricata supports landlock LSM security sandboxing to further improve security. Suricata can advise the Linux kernel to restrict access of its own processes to only the folders used by Suricata, so that in case of a possible security flaw the impact can be limited. Landlock requires Linux kernels >= 5.13 and needs to be activated in the kernel, which should be default since Debian Bookworm. This can be tested: dmesg | grep landlock || journalctl -kb -g landlock The suricata.yaml of this package comes with preconfigured settings, but landlock disabled by default, because kernel support can't be guaranteed in container deployments. If supported, simply activate it by this setting in suricata.yaml: 'landlock.enabled: yes' Please note that some Suricata default directories like 'default-rule-path', 'default-log-dir' and the state-dir '@e_localstatedir@' does not need to be named explicitly in the directories section, since they are added automatically by Suricata itself. See the upstream documentation for further details: https://docs.suricata.io/en/latest/configuration/landlock.html#using-landlock-lsm Initial configuration --------------------- Suricata cannot be used in a meaningful way without being adapted to the local network. At least the following settings of /etc/suricata/suricata.yaml should be reviewed before the daemon is started: * the capture interface in the 'af-packet' section, which has to match an interface of this system. The interface names can be listed with 'ip addr'. The value shipped by upstream is 'eth0', which does not exist on most systems. * the 'HOME_NET' variable in the 'vars' section, which should cover the address of the monitored interface and all local networks in use. The default already includes the RFC 1918 networks. Rules are not part of this package, see the section about updating rules below. Note that Suricata is also useful without any rules, since it logs metadata about the observed network traffic. See the upstream quickstart guide for a more detailed walkthrough: https://docs.suricata.io/en/latest/quickstart.html Daemon system integration ------------------------- The suricata daemon comes preconfigured to run as a system daemon with systemd, in af-packet mode and using /etc/suricata/suricata.yaml as configuration. The service is not enabled and not started when the package is installed, because the shipped configuration does not fit any particular system and because Suricata is also frequently installed just to analyse pcap files. Once /etc/suricata/suricata.yaml has been adapted as described above, you can start/stop the daemon with: sudo systemctl start suricata.service and sudo systemctl stop suricata.service To start the daemon on every boot, run: sudo systemctl enable suricata.service If the configured capture interface does not exist, Suricata terminates with a fatal error and the service ends up in the 'failed' state. The journal shows the offending interface name: journalctl -u suricata.service You can copy /usr/lib/systemd/system/suricata.service to /etc/systemd/system/suricata.service and adapt the configuration to your needs. Alternatively, you can override the command line (ExecStart) in the packaged systemd unit file using systemd’s drop-in feature [1]. For example, to start the service in nfqueue mode with queue, create a file /etc/systemd/system/suricata.service.d/override.conf with the following content: [Service] ExecStart= ExecStart=/usr/bin/suricata -D -q 0 -c /etc/suricata/suricata.yaml --pidfile /var/run/suricata/suricata.pid This overrides the default af-packet start by first clearing the previous ExecStart directive and then sets a new one, which you can now tailor as you wish. Then run sudo systemctl daemon-reload and then sudo systemctl restart suricata.service [1] https://www.freedesktop.org/software/systemd/man/latest/systemd.unit.html#id-1.14.3 Updating Rules -------------- You should edit /etc/suricata/suricata.yaml and adjust it to fit your needs. The recommended way to update rules is via suricata-update (also packaged in Debian). Please consult its documentation for more details: https://suricata-update.readthedocs.io