Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: [Snort-devel] Multirule inspection engine

From: Marc Norton <marc.norton(at)sourcefire.com>
Date: Mon Jun 23 2003 - 15:53:27 EDT


The Wu manber and most multi-pattern search engines find all occurrences of patterns. However, remember snort only logs one event per packet. So, we queue up all of the occurrences, and select one. Usually the longest content that matches is considered the most significant and accurate. Someday we'll log multiple packets.  

-----Original Message-----
From: snort-devel-admin@lists.sourceforge.net [mailto:snort-devel-admin@lists.sourceforge.net] Sent: Monday, June 16, 2003 3:54 PM
To: snort-devel@lists.sourceforge.net
Subject: [Snort-devel] Multirule inspection engine  

The engine (based on wu manber algorithm) finds all the occurrences of a pattern in a packet or the first one?  

Antonatos Spiros  



This SF.Net email is sponsored by: INetU Attention Web Developers & Consultants: Become An INetU Hosting Partner. Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission! INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php

Snort-devel mailing list
Snort-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-devel
Received on Mon Jun 23 16:09:56 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:06 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library