[Snort-sigs] Snort faster with rules containing a lot of content parameters

Alex McDonnell amcdonnell at sourcefire.com
Wed May 1 10:13:42 EDT 2019


Do you mean that your testing indicated that:

10 rules with 10 distinct content matches of 10 bytes
is faster than
10 rules with 2 distinct content matches of 10 bytes

Alex McDonnell
Talos

On Wed, May 1, 2019 at 5:24 AM Carl Nykvist via Snort-sigs <
snort-sigs at lists.snort.org> wrote:

> Hi!
>
> Me and a friend is doing a project with some testing, and we see that
> Snort has higher throughput(Packets/second) when the number of rules with
> content parameter increases, and when the number of rules with content
> parameter are very few, Snort has very low throughput.
>
> Does anyone know the reason for this?
>
> Regards,
> Carl
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs at lists.snort.org
> https://lists.snort.org/mailman/listinfo/snort-sigs
>
> Please visit http://blog.snort.org for the latest news about Snort!
>
> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
>
> Visit the Snort.org to subscribe to the official Snort ruleset, make sure
> to stay up to date to catch the most <a href="
> https://snort.org/downloads/#rule-downloads">emerging threats</a>!
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20190501/8b144694/attachment.html>


More information about the Snort-sigs mailing list