[Snort-users] acid, sig_priority

Chris Green cmg at ...671...
Tue Dec 2 18:11:01 EST 2003


Nicholas Bernstein <nick at ...10668...> writes:

> Could someone tell me what exactly sig_priority does? Is it a general
> threat level? i.e remote root could be 5 where info gathering might be
> 1? Am I way off? 

It's supposed to be.  It's not that useful currently ( and never has
been ).  Preprocessors generally use 5 and rules use 1-3.  Look at
classification.config for what is high/low.
-- 
Chris Green <cmg at ...1121...>
"I'm beginning to think that my router may be confused."





More information about the Snort-users mailing list