[Snort-users] Snort Performance Issues
bmc at ...312...
Fri Aug 11 09:00:12 EDT 2000
Fabio Pietrosanti wrote:
> There's some mathematical operation to calculate the calculation power for
> Something like :
> NRules * NTrafficToAnalyze or similar ?
No, that wouldn't be very useful. Many snort rules require looking at
payload, or parsing through a preprocessor. Any of these types of rules
add an enormous amount of time (comparatively) to the rules where only
tcp flags are checked. Because of the variety of rule sets available,
equation would be huge.
The MITRE Corporation
More information about the Snort-users