Skip to main content

I’m building Suri Oculus 4.0 — host behavior profiling and anomaly analysis on top of Suricata

0
Medium
Published: 09/30/2026 (09/30/2026, 12:46:27 UTC)
Source: Reddit Cybersecurity

Description

Suri Oculus 4.0 is an open-source network monitoring and analysis platform built on top of Suricata, designed to provide host behavior profiling and anomaly analysis. It aggregates network data such as flows, DNS, TLS, ports, and Suricata alerts to build behavioral profiles for hosts, enabling detection of deviations from normal activity. The platform uses a combination of C++, Python, Redis, and web technologies to deliver high-performance log management and analysis. It is intended to complement Suricata's signature-based detection with statistical anomaly detection using Isolation Forest. Pre-built packages are available for multiple Linux distributions. This is a security tool project, not a vulnerability or exploit.

Reddit Discussion

r/cybersecurity·posted by u/PurpleReindeer434
00

I’ve been working on Suri Oculus 4.0, an open-source network monitoring and analysis platform built around Suricata, and I’d like to share the current state of the project with the community.

The basic idea behind Suri Oculus is simple: Suricata already provides a huge amount of useful network data through EVE JSON, but as the amount of traffic grows, investigating individual events becomes increasingly difficult.

Suri Oculus adds an additional processing and visualization layer on top of Suricata.

The current architecture looks roughly like this:

Network traffic | v Suricata | v EVE JSON | v daemonmove | v Redis | +-------------------+ | | v v Host Behavior Anomaly Analysis Fingerprinting | | +---------+---------+ | v C++ REST API | v Suri Oculus UI 

The backend is primarily written in C++ using Pistache, while Python/FastAPI is used for parts of the data analysis pipeline. Redis is used for event processing and aggregated host data. The frontend is implemented in HTML and plain JavaScript.

One of the main areas I have been working on for version 4.0 is HBF — Host Behavior Fingerprinting.

Instead of looking only at individual Suricata events, HBF gradually builds a behavioral profile for hosts observed on the network.

For each device, Suri Oculus can aggregate information such as:

  • network flows
  • DNS activity
  • TLS connections and SNI
  • destination ports
  • TCP/UDP/ICMP activity
  • Suricata alerts
  • first and last observed activity
  • general activity statistics

The idea is to provide another perspective on Suricata data.

Instead of asking only:

“What event occurred?”

we can also ask:

“How does this host normally behave on the network?”

For example, a workstation may normally communicate with a relatively stable set of services, use a predictable set of destination ports, and generate characteristic DNS and TLS activity. A significant change in that behavior does not automatically indicate an attack, but it can provide useful context for further investigation.

Suri Oculus also contains an anomaly-analysis layer. Suricata events are converted into numerical features and analyzed using Isolation Forest. This is not intended to replace Suricata signatures. The two approaches address different problems: Suricata detects traffic matching defined rules, while anomaly analysis can highlight activity that differs statistically from previously observed data.

Another goal for version 4.0 was to make the project easier to install and test.

Pre-built packages are now available for:

  • Fedora 42, 43 and 44
  • RHEL 9 and 10
  • Debian 12 and 13
  • Ubuntu 22.04 and 24.04

RPM and DEB packages are published together with SHA-256 checksums and GPG signatures.

The project currently consists of several components, including the C++ backend, web frontend, daemonmove event-processing service, supporting tools, and Pistache packages.

I’m particularly interested in feedback from people who already use Suricata in real networks.

Some questions I’m currently interested in:

  • What host-level information would be most useful when investigating Suricata events?
  • Which behavioral indicators would you expect to see in a host profile?
  • Would historical HBF snapshots be useful for comparing device behavior over time?
  • Which Suricata event types should receive more attention in behavioral analysis?

Project website and downloads:

https://suri-oculus.com/

Feedback, testing results, architecture suggestions, and criticism are welcome.

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 13:03:03 UTC

Technical Analysis

Suri Oculus 4.0 enhances Suricata by adding a host behavior fingerprinting layer that aggregates various network activity metrics per device to build behavioral profiles. It also includes an anomaly analysis layer that converts Suricata events into numerical features analyzed by Isolation Forest to detect statistical deviations. The system architecture involves Suricata generating EVE JSON logs, which are processed by daemonmove and stored in Redis for fast access. The backend is primarily C++ with Python components, and the frontend is web-based. The project aims to improve investigation efficiency by providing context on normal host behavior alongside traditional event data. It is designed for deployment on both high-end and resource-constrained devices and supports multiple Linux distributions with signed packages. No security vulnerability or exploit is described.

Potential Impact

There is no direct security impact or vulnerability described. Suri Oculus 4.0 is a security monitoring and analysis tool intended to enhance network visibility and anomaly detection capabilities. It does not introduce a security threat but rather aims to improve detection and investigation of suspicious network activity.

Defensive Guidance

Not applicable. This is a security tool project, not a vulnerability or threat requiring mitigation. Users interested in enhanced Suricata data analysis may consider deploying Suri Oculus 4.0 as part of their security monitoring stack.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:analysis","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["analysis"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6abd087f2a4e24523d05e7d4

Added to database: 09/30/2026, 13:02:55 UTC

Last enriched: 09/30/2026, 13:03:03 UTC

Last updated: 09/30/2026, 14:47:56 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses