|
|||||||||||
|
[Snort-devel] snort signatures categorization
From: karim hassib <k_hassib(at)hotmail.com>
Date: Thu Jun 19 2003 - 18:14:49 EDT hi i don't know if this is the correct list for my issue or not, but anyway. we're a couple of students at cairo university in egypt and we're trying to write an ids and we're using the sigantures of snort as an attack signatures. now we're writing the analysis engine and the parser and we want to try to do it in a more detailed way than snort, we want at the end to have more categories but less signatures in each category to have less pattern matching in the content and to be faster . the problem is that when we started looking at the files it's difficult to get these more categories based on the source port, dest port and source and destination ips only. so do you have any suggestions on how to try to group them together, how does snort do it exactly? i took a look at the lisa paper but i need to know how the categories are determined? based on the files only, or do we get more than one category in each file? best regards and thanks for your time MSN 8 with e-mail virus protection service: 2 months FREE* ------------------------------------------------------- This SF.Net email is sponsored by: INetU Attention Web Developers & Consultants: Become An INetU Hosting Partner. Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php _______________________________________________ Snort-devel mailing list Snort-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-devel Received on Thu Jun 19 18:32:45 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:06 EDT |
||||||||||
|
|||||||||||