Exploits and other threats

I’m not sure if an IPS is really needed on a VPS. It’s good on a gateway to protect a whole network IMO. A blocking IPS combined with false positives leads to issues so it needs a good setup as we know from NS7.
I didn’t check all listed exploits but some are older (not working anymore on updated systems) and others are about specific apps or devices like D-Link or CCTV.

But Crowdsec seems to support suricata, see also https://app.crowdsec.net/hub/author/crowdsecurity/collections/suricata
There’s a suricata project that has instructions for podman: GitHub - jasonish/docker-suricata: A Suricata Docker image.
So it could be possible to implement an IPS in NS8…

See also NethSecurity project milestone 8.4 - #7 by mrmarkuz about the difference between snort/suricata and crowdsec.

1 Like