Snort mailing list archives

Re: Snort faster with rules containing a lot of content parameters


From: Alex McDonnell <amcdonnell () sourcefire com>
Date: Wed, 1 May 2019 10:13:42 -0400

Do you mean that your testing indicated that:

10 rules with 10 distinct content matches of 10 bytes
is faster than
10 rules with 2 distinct content matches of 10 bytes

Alex McDonnell
Talos

On Wed, May 1, 2019 at 5:24 AM Carl Nykvist via Snort-sigs <
snort-sigs () lists snort org> wrote:

Hi!

Me and a friend is doing a project with some testing, and we see that
Snort has higher throughput(Packets/second) when the number of rules with
content parameter increases, and when the number of rules with content
parameter are very few, Snort has very low throughput.

Does anyone know the reason for this?

Regards,
Carl
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules:
https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure
to stay up to date to catch the most <a href="
https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

Current thread: