|
|||||||||||
|
[Snort-devel] New feature in snort - mark modified packets
From: Martin Olsson <elof(at)sentor.se>
Date: Mon Jun 23 2003 - 11:52:03 EDT Could snort include a label indicating the origin of the logged packet?
original no longer exist)
packet, but the original still exist in memory (when this was logged)) N = Payload does not exist. The alert is built on statistics, counters, timers... ...or maybe this is better: A field containing a list of all the functions that have modified the packet in some way. Maybe several preprocessors (and some output plugin) have modified the packet between the capture and the log, then just one position for the label is not enough.
When the packet is captured from the interface the list contain only:
The above would be the parsed text. The logged data would be much smaller since O, U, M, A and N as well as the preprocessors have numeric representations (see the file generators). I hope this could be included in snort. I think it would add to the understanding of the alert when analyzed by an operator. Anyone else think this is a good idea?
Martin Olsson
This SF.Net email is sponsored by: INetU Attention Web Developers & Consultants: Become An INetU Hosting Partner. Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php Snort-devel mailing list Snort-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-devel Received on Mon Jun 23 12:12:52 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:06 EDT |
||||||||||
|
|||||||||||