[Snort-devel] Need help !!! Dynamic concatenation of IP/ MAC address for arpspoof

Mohamed Makthum makthum at ...2499...
Thu Apr 18 21:57:48 EDT 2013

Hello everyone,

                                 I am a graduate student and I am quite
interested in IDS system. I want to do my Masters project on IDS. After
considerable amount of googling and study I learned about snort and it
working mechanism. Currently for arpspoof preprocessor we have to provide
the static IP/Mac address mapping for it work . I was thinking of
implementation(script) where IP / Mac address table can be retrieved and
updated in snort.conf. 


My questions 


1)      Is there such an implementation or script available today ?


2)      If not is such an implementation even possible to retrieve the ip /
Mac mapping from DHCP server ?


3)      If implemented will it be useful ?


I need help and suggestion from all you guyz and sorry if you find these
novice question.


I am just a beginner and but I like to learn . Thanks for your time and




-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-devel/attachments/20130418/db6be70b/attachment.html>

More information about the Snort-devel mailing list