Full Disclosure mailing list archives

Re: Snort as IDS/IPS in mission-critical enterprise network


From: coderman <coderman () gmail com>
Date: Fri, 9 Dec 2005 10:14:36 -0800

On 12/9/05, J.A. Terranson <measl () mfn org> wrote:
... last I looked, SNORT was
being used on circuits as large as OC12s.

The problem isn't going to be your sensor (SNORT et al), but your back end
software - *that* part is a bitch!

what ever happened to FPGA/hardware based NIDS classifiers?  There
seemed to be a number of papers and even some open source (open cores)
code to do 10GigE with ease.

still in the research labs?
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: