[Snort-sigs] Snort faster with rules containing a lot of content parameters
amcdonnell at sourcefire.com
Wed May 1 10:13:42 EDT 2019
Do you mean that your testing indicated that:
10 rules with 10 distinct content matches of 10 bytes
is faster than
10 rules with 2 distinct content matches of 10 bytes
On Wed, May 1, 2019 at 5:24 AM Carl Nykvist via Snort-sigs <
snort-sigs at lists.snort.org> wrote:
> Me and a friend is doing a project with some testing, and we see that
> Snort has higher throughput(Packets/second) when the number of rules with
> content parameter increases, and when the number of rules with content
> parameter are very few, Snort has very low throughput.
> Does anyone know the reason for this?
> Snort-sigs mailing list
> Snort-sigs at lists.snort.org
> Please visit http://blog.snort.org for the latest news about Snort!
> Please follow these rules:
> Visit the Snort.org to subscribe to the official Snort ruleset, make sure
> to stay up to date to catch the most <a href="
> https://snort.org/downloads/#rule-downloads">emerging threats</a>!
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-sigs