OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: planetf1 on May 28, 2024, 08:03:42 PM

Title: Duplicate/invalid rules
Post by: planetf1 on May 28, 2024, 08:03:42 PM
I have suricata IDS running under opnsense.

I currently have all the ET Telemetry (proofpoint) rules enabled, along with abuse.ch

In my log I see many signature warnings ie:

Quote2024-05-23T16:10:05   Error   suricata   [100953] <Error> -- error parsing signature "alert dns $HOME_NET any -> any any (msg:"ET COINMINER Observed DNS Query to Browser Coinminer (crypto-loot[.]com)"; dns.query; content:"crypto-loot.com"; endswith; classtype:coin-mining; sid:2024828; rev:5; metadata:affected_product Any, attack_target Client_Endpoint, created_at 2017_10_09, deployment Perimeter, former_category COINMINER, malware_family CoinMiner, signature_severity Major, tag Coinminer, updated_at 2020_09_15, mitre_tactic_id TA0040, mitre_tactic_name Impact, mitre_technique_id T1496, mitre_technique_name Resource_Hijacking;)" from file /usr/local/etc/suricata/opnsense.rules/emerging-coinminer.rules at line 62   
2024-05-23T16:10:05   Error   suricata   [100953] <Error> -- Duplicate signature "alert dns $HOME_NET any -> any any (msg:"ET COINMINER Observed DNS Query to Browser Coinminer (crypto-loot[.]com)"; dns.query; content:"crypto-loot.com"; endswith; classtype:coin-mining; sid:2024828; rev:5; metadata:affected_product Any, attack_target Client_Endpoint, created_at 2017_10_09, deployment Perimeter, former_category COINMINER, malware_family CoinMiner, signature_severity Major, tag Coinminer, updated_at 2020_09_15, mitre_tactic_id TA0040, mitre_tactic_name Impact, mitre_technique_id T1496, mitre_technique_name Resource_Hijacking;)"

There are 10,000s or more of these.

When I look on disk, I see that I do have 2 files with this sid in
* /usr/local/etc/suricata/opnsense.rules/emerging-coinminer.rules
* /usr/local/etc/suricata/rules/emerging-coinminer.rules

In suricata.yaml I see:

default-rule-path: /usr/local/etc/suricata/opnsense.rules

I'm not sure on the process here, I am guessing one copy is the raw download, the other may be after modifications? But if so, why are these errors being reported on suricata startup? I'd presume it would only look at the opnsense.rules directory?

Title: Re: Duplicate/invalid rules
Post by: someone on June 10, 2024, 09:41:42 PM
First line says cant parse
Sometimes its an error in the rule, sometimes syntax, setup, language
I first ran into this back when I was converting snort ET rules to suricata rules
Cant run snort rules on suricata and vice versa
Title: Re: Duplicate/invalid rules
Post by: someone on June 10, 2024, 09:49:00 PM
Just so you know I get them also
I dont delete them
I try and fix them
I have fixed many
Sometimes its simple, syntax, punctuation
Title: Re: Duplicate/invalid rules
Post by: someone on June 26, 2024, 01:40:23 AM
Sorry your having trouble
Opnsense will set up your rules, done in proper order, no trouble
One of the paths you gave is the rule directory, not sure about the other
But it doesnt matter as opnsense will load correctly by default
You should not have that trouble with duplicates, not sure how you got them
Dont download them twice, it handles updates by default
Title: Re: Duplicate/invalid rules
Post by: someone on June 26, 2024, 10:23:36 PM
You didnt mention which version you are using
Version 24 is running very smooth
I had a few problems with earlier version, nothing serious
Title: Re: Duplicate/invalid rules
Post by: MagikMark on June 28, 2024, 01:58:51 AM
I get these also in OpnSense and pfSene.  The maintainer of suricata in pfsense said that this is because some rules and designed for Snort which may not be compatible with Suricata
Title: Re: Duplicate/invalid rules
Post by: notspam on October 21, 2024, 10:03:27 PM
- clean install of 24.7
- update to 24.7.6
- install the whole plugins like suricata
- enable rules
- save
- download and install
- activate service as ips
- perhaps i press hours later the "download and install" button again

result:
- dozens of duplicate entries
- instable ips service

=> how can i fix this ?
=> how is the misbehaviour fixes in future releases ?

Thanks for your help and your hard work @ opnsense

Title: Re: Duplicate/invalid rules
Post by: guenti_r on January 09, 2025, 12:07:12 PM
This issue shows up when the etpro-telemetry & os-intrusion-detection-content-et-open is installed and the etpro-sensor is switched to et_open because of connectivity issues.
So you have two different et-open sets.

See https://forum.opnsense.org/index.php?topic=45112.0 (https://forum.opnsense.org/index.php?topic=45112.0)
Title: Re: Duplicate/invalid rules
Post by: flaviuvlaicu on January 18, 2025, 12:50:11 PM
I remove the ETPRO Telemetry and now this. I have double ET Open rules. Does someone know how to fix this?

Title: Re: Duplicate/invalid rules
Post by: flaviuvlaicu on January 18, 2025, 12:58:15 PM
Quote from: guenti_r on January 09, 2025, 12:07:12 PMThis issue shows up when the etpro-telemetry & os-intrusion-detection-content-et-open is installed and the etpro-sensor is switched to et_open because of connectivity issues.
So you have two different et-open sets.

See https://forum.opnsense.org/index.php?topic=45112.0 (https://forum.opnsense.org/index.php?topic=45112.0)

Did you manage to solve the issue with the duplicate Open rulesets?
Title: Re: Duplicate/invalid rules
Post by: RamiroJohnson on February 16, 2025, 05:55:59 PM
Quote from: flaviuvlaicu on January 18, 2025, 12:58:15 PM
Quote from: guenti_r on January 09, 2025, 12:07:12 PMThis issue shows up when the etpro-telemetry & os-intrusion-detection-content-et-open is installed and the etpro-sensor is switched to et_open because of connectivity issues.
So you have two different et-open sets.

See https://forum.opnsense.org/index.php?topic=45112.0 (https://forum.opnsense.org/index.php?topic=45112.0)Block Blast (https://blockblast.org)

Did you manage to solve the issue with the duplicate Open rulesets?
What happens if the duplicate open rule changes?
Title: Re: Duplicate/invalid rules
Post by: Trannie on March 10, 2025, 08:42:21 AM
Quote from: guenti_r on January 09, 2025, 12:07:12 PMThis issue shows up when the etpro-telemetry & os-intrusion-detection-content-et-open is installed and the etpro-sensor is switched to et_open because of connectivity issues.
So you have two different et-open sets.

See https://forum.opnsense.org/index.php?topic=45112.0 (https://forum.opnsense.org/index.php?topic=45112.0) Love Pawsona (https://lovepawsonaquiz.org/)
Thanks for pointing that out! It makes sense that having two different et-open sets could cause issues.