Writing Snort Signatures | Check Point WAF

Snort usage in CloudGuard WAF

It is possible to use a signature language called Snort to create or download custom signatures to be enforced by CloudGuard WAF. For exact details how to configure:

Snort Rules

There are many guides and video tutorials online on how to write Snort rules, and you can read the full documentation in Snort.

This page will provide a short guide on top of those links.

Snort rules overview

Each Snort rule is written in a single line and is made up of two parts: the header and the keywords.

The header section has a fixed format made up of seven distinct elements, and answers the questions: What action to take (detect or drop), and on which connections (remember that Snort was originally conceived as a layer 3 IDS) it should apply to.

The keywords section is made of parenthesis that holds a variable set of distinct instructions called keywords, and each keyword is terminated by a semi-colon.

The Snort header

The Snort header is made of seven parts:

  1. Action.
  2. Protocol.
  3. IP address or addresses.
  4. Port number or set of numbers.
  5. Direction operator.
  6. IP address or addresses.
  7. Port number or set of numbers.

The header is intended to answer the questions: What action to take (detect or drop), and on which connections (remember that Snort was originally conceived as a layer 3 IDS) it should apply to. However, in our setting these definitions will be overridden by what the user definitions in the system.

Since that is the case, the simplest thing to do is just copy a standard header for any rule that you write, like this one:

alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS

The Snort keywords section

The Snort keywords section contains a variable number of keywords - each one of them represent one "thing" that the rule should do.

We can divide the keywords into three categories:

  1. Metadata keywords - these keywords provide general information on the rule, the log that will be produced, etc.
  2. Context keywords - these keywords express on which part of the traffic (in our case, which part of the HTTP protocol) will the inspection keywords apply.
  3. Inspection keywords - these keywords test the traffic for certain conditions. They are the ones that determine if the rule is matched and an action should be taken.

Metadata keywords

Metadata-type keywords can be divided into three categories:

Must-have metadata keywords

msg: "Testing CloudGuard WAF Snort";

flow: to_server,established;

service: http;

Recommended metadata keywords

sid: 12345;

rev: 1;

Optional metadata keywords

reference: url,www.acunetix.com;

Context keywords

Context-type keywords define which section of the HTTP protocol the following inspection keywords will refer to. So when wanting to check the URI, you need to first mention the appropriate keyword and then all the following inspection keywords will apply to the URI - until another context keyword will appear.

By default Snort scans the raw packet, not parsed HTTP. Since we are working in Layer 7 only, this is not possible for us to do. So you must use a context keyword before using any inspection keywords.

The main context keywords you want to know are:

Inspection keywords

Inspection-type keywords determine if the request's data (in the section specified by the previous context keyword) meets a certain condition. If it does, then the keywords are said to be matched. If all the inspection keywords match then the rule is said to be matched and the appropriate action (drop and/or send log) will take place.

There are several inspection keywords, and each of them usually have several options. Here we are going to present only the basic syntax of two inspection keywords - this is sufficient for most purposes.

content: "attack data";

pcre: "/hello\s*world/;"