New Slips version v1.1.24 is here!

Our team is excited to share the latest news and features of Slips, our behavioral-based machine learning intrusion detection system.

Quick links:

What We Are Particularly Excited About

In this release we are particularly excited about these new Slips features:

  • Redesign the local web interface with Overview, Alerts, Evidence, Hosts, Firewall, ARP poisoning, P2P, Logs, Configuration, and Whitelists tabs.

  • Require a password to log in to the web interface.

  • Show host score history, firewall blocks, ARP poisoning events, and P2P statistics in the web interface.

  • Add firewall rule recovery when Slips shuts down.

  • Exclude P2P flows from port scan evidence, ML detection, and scoring.

  • Speed up whitelist lookups.

  • Fix Slips generating duplicate alerts.

  • Reduce CPU and memory usage.

  • Enable TLS certificate verification and fix an authentication bypass and Redis password handling in Iris.

  • Fix issues disabling detections in slips.yaml.

Check the full list of changes in our release page: https://github.com/stratosphereips/StratosphereLinuxIPS/releases/tag/v1.1.24

Learn more!

Wondering what Slips is capable of? Check out these demo presentations:

How to contribute

For those interested in contributing to Slips:

Get in Touch

Feel free to join our Discord server and ask questions, suggest new features or give us feedback. PRs and Issues are welcomed in our repo.