Skip to main content

IDS Rule Converter

CI Engine Validation Security License: Apache-2.0

Stop guessing whether a converted IDS rule still means the same thing.

IDS Rule Converter is a secure, loss-aware, one-file Python toolkit for parsing, validating, analyzing, comparing, and converting Snort and Suricata rules. It defaults to refusing uncertain translations instead of silently dropping or weakening detection logic.

The runtime has no third-party Python dependencies. Copy snort_suricata_rule_converter.py to a system with Python 3.10 or newer and run it directly.

Version 4.0.1 is the current release. Download the verified standalone Python runtime or the deterministic documentation ZIP. The release page also provides the SPDX SBOM, SHA-256 checksums, release evidence, and GitHub provenance. See RELEASING.md for the exact artifact and publication gates.

Why this tool is different

Rule conversion is not a keyword replacement problem. Sticky buffers, content modifier placement, service declarations, application protocols, regular expressions, and engine-specific actions all affect detection behavior.

IDS Rule Converter provides:

  • Ordered parsing that preserves repeated options and content modifier context
  • Strict, fail-safe conversion between Snort 2, Snort 3, and Suricata 8
  • Explicit rejection files and machine-readable reports for unsafe rules
  • Native JSON and SARIF output for automation and code scanning systems
  • Duplicate SID, conflicting SID, keyword, protocol, and action analysis
  • Semantic ruleset comparison by GID, SID, revision, and fingerprint
  • Offline Panorama IPS Signature Converter 2.0.4 compatibility preflight
  • Safe download support for allowlisted Cisco Talos community feeds
  • Archive defenses against traversal, links, special files, duplicate paths, encrypted ZIP entries, Windows device names, and decompression abuse
  • Atomic output writes, overwrite refusal, and input replacement protection
  • No telemetry and no implicit network access

Quick start

python snort_suricata_rule_converter.py --help
python snort_suricata_rule_converter.py validate input.rules
python snort_suricata_rule_converter.py analyze input.rules --output analysis.json

Convert a Snort 3 ruleset to Suricata. Strict mode is the default, so no ruleset is written if any rule has an unsafe or unverified mapping.

python snort_suricata_rule_converter.py convert input.rules --source-dialect snort3 --target suricata --output converted.rules --report conversion.json

To export only the verified subset, preserve every rejected source rule, and receive a detailed report:

python snort_suricata_rule_converter.py convert input.rules --source-dialect snort3 --target suricata --output accepted.rules --allow-partial --rejected-output rejected.rules --report conversion.json

An intentional partial result exits with code 2 so automation cannot mistake it for a complete conversion.

Strict and reviewed partial results

Synthetic two-rule IDS conversion comparison showing strict mode writing no ruleset and reviewed partial mode separating one accepted rule, one rejected rule, and a JSON report while returning exit code 2.

Constructed test data. Strict mode writes no converted ruleset when one mapping is unsafe. An explicit partial export preserves accepted rules, rejected source rules, and the report as one review set. Native target validation is still required.

Commands

Command Purpose
validate Parse rules and report structural or identifier problems
analyze Inventory rules, keywords, actions, protocols, duplicates, and conflicts
convert Convert to Snort 2, Snort 3, Suricata, or structured JSON
panorama-preflight Check and batch rules for Panorama plugin 2.0.4
diff Compare two rulesets by GID and SID
list-sources Show built-in HTTPS feed definitions
fetch Download and optionally extract an allowlisted rule feed safely

See QUICK_REFERENCE.md for copy-ready examples.

Conversion safety model

The default behavior is intentionally conservative:

  1. The complete input must parse successfully.
  2. Each rule is checked against the declared target dialect.
  3. Verified transformations preserve option order and buffer context.
  4. A rule with an unsafe mapping is rejected, not approximated.
  5. Strict conversion writes nothing when any rule is rejected.
  6. Partial conversion requires both a rejection file and a JSON report.
  7. Unknown target keywords require the explicit --allow-unverified opt-out.

Important verified transformations include Snort 3 and Suricata HTTP sticky buffers, Snort 2 HTTP content modifiers, safe service mappings, TLS protocol naming, selected SIP options, bufferlen to bsize, stream_size syntax, fast-pattern offsets, and compatible tag syntax.

The converter rejects ambiguous multi-service rules, unsupported target actions, conflicting application protocols, unsafe buffer arguments, packet and application-layer conflicts, unsupported BER and DCE options, and other cases where equivalence has not been established.

Always run the target engine's native configuration test before deployment. Successful parsing proves that an engine accepts a rule. It does not prove that every rule will detect identical traffic under every engine configuration.

Panorama preflight

The Panorama command performs an offline compatibility review for IPS Signature Converter plugin 2.0.4. It checks documented action, protocol, condition, PCRE, threshold, reference, case-sensitivity, negation, and positional limits. Accepted source rules are divided into batches of no more than 100 rules and 8 MB.

python snort_suricata_rule_converter.py panorama-preflight input.rules --output-dir panorama-review

The tool never connects to Panorama and never uploads a rule.

Safe feed retrieval

Network access occurs only when fetch is explicitly invoked. Built-in sources use HTTPS and an exact hostname allowlist. Redirects outside that allowlist are refused.

python snort_suricata_rule_converter.py list-sources
python snort_suricata_rule_converter.py fetch --source snort3-community --output-dir downloads --extract

The downloaded archive, SHA-256 metadata, and extracted files are local outputs. Rules remain subject to their provider's terms and are not part of this project's Apache 2.0 license.

Test evidence

The 4.0.1 release-readiness tree contains 64 automated tests covering parsing, conversion, reports, Panorama checks, overwrite controls, URL and redirect policy, malicious archives, repository text policy, and deterministic release construction. CI exercises Python 3.10 through 3.14 on Linux, Python 3.12 on Windows and macOS, and both conversion directions against pinned Snort 3.10.0.0 and Suricata 8.0.6 containers.

The larger 4,017-rule Cisco Talos community corpus was validated for version 4.0.0. Snort accepted the full same-dialect round trip with zero warnings. The fail-safe Suricata conversion accepted 3,762 rules, rejected 255 with recorded reasons, and passed native validation with zero errors. Suricata emitted 71 nonfatal duplicate-buffer warnings for source patterns that intentionally revisit an earlier sticky buffer.

Version 4.0.1 changes output-file race handling, feed URL validation, repository controls, and release construction. It does not change conversion semantics. The large third-party corpus has not been rerun for the candidate, so its result is kept explicitly separate from the current hosted native-fixture checks. Full commands, container digests, and scope are recorded in docs/TESTING.md.

Exit codes

Code Meaning
0 Operation completed without blocking findings
1 Operational failure, unsafe path, network failure, or invalid invocation
2 Validation findings, conflicts, rejected rules, or an intentional partial result
130 Interrupted by the operator

Development

python -m pip install -r requirements-dev.txt
python -m ruff format --check .
python -m ruff check .
python -m bandit -q -r snort_suricata_rule_converter.py scripts
python -m pip_audit -r requirements-dev.txt
python -m unittest discover -s tests -v

The production runtime remains one file. Tests, documentation, and repository automation are separate so the executable itself stays portable.

Security and privacy

  • Rule files are processed locally.
  • The tool contains no credentials, tokens, account IDs, or environment-specific resource names.
  • Output files are UTF-8 and written atomically.
  • Existing outputs are refused unless --force is supplied.
  • --force cannot replace an input file.
  • Report suspected vulnerabilities through the private process in SECURITY.md.

License

The converter, tests, and project documentation are licensed under the Apache License 2.0. Third-party rules, vendor documents, and downloaded feeds are not redistributed by this repository and retain their original terms.

Snort is a registered trademark of Cisco. Suricata is a registered trademark of the Open Information Security Foundation. This project is independent and is not endorsed by either organization.

Metadata

Release files for ids-rule-converter 4.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ids-rule-converter 4.0.2
File Size Uploaded
ids_rule_converter-4.0.2.tar.gz 215.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ids-rule-converter 4.0.2
File Interpreter ABI Platform
ids_rule_converter-4.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 355.8 kB

Release files / ids_rule_converter-4.0.2.tar.gz

Download URL ids_rule_converter-4.0.2.tar.gz
Size 215.1 kB
Tags Source
SHA-256 checksum
How to use checksums
9e5b74b741ab9425799b18ceead72dc48d71688ff38fe9ded5c032a20fb451ce
BLAKE2b-256 checksum
How to use checksums
1f2867df86e63189f75196747abbc2ab9b87825c9c00b46e31587658d620c385
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release files / ids_rule_converter-4.0.2-py3-none-any.whl

Download URL ids_rule_converter-4.0.2-py3-none-any.whl
Size 140.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6522de230ae1032a560363ff1887dbcc744888ccfd6e738f8b10cb8d48739cc2
BLAKE2b-256 checksum
How to use checksums
a34006e304644990bf74f0af8bb12729ab05b09d4e91357c3bf15db3f4340bf9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

4.0.2 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page