[Snort-openappid] OpenAppID rules (New Call)

Carlos Rodriguez Hernandez crodriguezh.ext at ...109...
Fri Nov 6 12:25:06 EST 2015

Thanks for your answer, Joel.

Of course OpenAppID adds great functionality to Snort, and the performance
penalty is totally acceptable.

I was just thinking that if detection engine only evaluate some rules
depending on the application this would decrease the number of rules to
evaluate and also the number of false positives/negatives, so additionally
improve Snort, coupled with the new functionality to detect application,
which is very interesting and useful for the whole community.

Carlos Rodríguez Hernández
*Fellow Developer*
redborder.net | +34 609477932

This email, including attachments, is intended exclusively for its
addressee. It contains information that is CONFIDENTIAL whose disclosure is
prohibited by law and may be covered by legal privilege. If you have
received this email in error, please notify the sender and delete it from
your system.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-openappid/attachments/20151106/cce4443a/attachment.html>

More information about the Snort-openappid mailing list