[Snort-sigs] Snort Rule optimizer

skaf skaf at ...2517...
Thu May 27 02:17:10 EDT 2004


Hello,
 
I am new to your mailing list and to snort, i am doing a research on
Snort IDS and especially on how the preprocessors and detection engine
works, 
 
I read about the new detection engine and the rule optimiser, I bought
the new snort 2.1 book but I cant find lots of documentation on how the
rule Optimiser works (and the Multi rule pattern match)
 
Anyone have links on where do i get useful information about these
subjects ?
 
Does the Rule optimiser creates the Rule sets on every packet or they
are created during initialisation ?
 
Thanks
 
Rawad
 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20040527/5ad71029/attachment.html>


More information about the Snort-sigs mailing list