[Snort-sigs] Snort Rule optimizer
jennifer.steffens at ...435...
Thu May 27 08:18:18 EDT 2004
While Sourcefire generally collects basic contact information from
people downloading our white papers, I would like to make these papers
directly available to the folks on this list. You can find them at
Director, Product Marketing
On May 27, 2004, at 9:59 AM, Daniel J. Roelker wrote:
> Sourcefire has whitepapers on the design and implementation of the
> 2.0 detection engine (since Sourcefire paid for the design and
> development). You can check them out at:
> On Thu, 2004-05-27 at 05:27, skaf wrote:
>> I am new to your mailing list and to snort, i am doing a research on
>> Snort IDS and especially on how the preprocessors and detection engine
>> I read about the new detection engine and the rule optimiser, I bought
>> the new snort 2.1 book but I cant find lots of documentation on how
>> rule Optimiser works (and the Multi rule pattern match)
>> Anyone have links on where do i get useful information about these
>> subjects ?
>> Does the Rule optimiser creates the Rule sets on every packet or they
>> are created during initialisation ?
> Daniel Roelker
> Software Developer
> Sourcefire, Inc.
> This SF.Net email is sponsored by: Oracle 10g
> Get certified on the hottest thing ever to hit the market... Oracle
> Take an Oracle 10g class now, and we'll give you the exam FREE.
> Snort-sigs mailing list
> Snort-sigs at lists.sourceforge.net
More information about the Snort-sigs