Snort mailing list archives

Re: Snort Dynamic Preprocessor for BACnet


From: "Russ Combs (rucombs)" <rucombs () cisco com>
Date: Fri, 9 May 2014 13:01:01 +0000

Glad to hear you are making progress.  As for rate limiting, the closest thing would be rate_filter, although that is 
not a preprocessor.  The rate filter changes the action on a rule (eg from alert to drop).  You might try that out to 
see how it works and then look at the code to see if it helps you with your effort.

________________________________
From: highend root [highend () onycs com]
Sent: Thursday, May 08, 2014 10:16 AM
To: Russ Combs (rucombs)
Subject: Snort Dynamic Preprocessor for BACnet

Hello Mr. Combs,

I already contacted you at the end of March regarding the development
of a dynamic preprocessor for the BACnet building automation
protocol.
Work is in good progress so far but you may point me in the right
direction on how to implement a kind of stateful normalization.
As a simple example:

  Drop or limit the number of messages with the same content (or of the
  same type) within a time window.

Is there an implementation of similar kind within another preprcessor
which I could used as a guide?
An answer is very much appreciated.

Best Regards
Harry Haerpfer

------------------------------------------------------------------------------
Is your legacy SCM system holding you back? Join Perforce May 7 to find out:
&#149; 3 signs your SCM is hindering your productivity
&#149; Requirements for releasing software faster
&#149; Expert tips and advice for migrating your SCM now
http://p.sf.net/sfu/perforce
_______________________________________________
Snort-devel mailing list
Snort-devel () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-devel
Archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

Current thread: