Snort mailing list archives
Re: Snort architecture
From: Tony Robinson <trobinson () sourcefire com>
Date: Wed, 11 Jul 2012 12:23:27 -0400
From my experience the best documentation on snort's architecture is going
to be in: 1) the snort manual up on snort.org 2) the source code itself 3) the readme files for each portion of snort, included with the source code packages Not necessarily the answer most people want to hear, but I would recommend the snort manual and readme files to get a better understanding on how snort truly works - most of the books written for snort are outdated, or if they aren't outdated, they become outdated very quickly due to how often snort is updated. Readmes and snort.org manual are updated almost as frequently as, if not as frequenly as, the source code itself. Regards, -Tony On Wed, Jul 11, 2012 at 11:47 AM, Pratik Narang <pratik.cse.bits () gmail com>wrote:
Dear Snort users, Can anyone please help me out with Snort's architecture- based on their own knowledge, or documentation or books or references available for it. I wish to understand the architecture at a high level of abstraction and understand the various modules, their dependencies, what part of the source code does what, where does the signature engine lie, where is the anomaly engine, etc. Thanks... ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
-- Tony Robinson Security Consultant I SourceFIRE Professional Services Division
------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Snort architecture Pratik Narang (Jul 11)
- Re: Snort architecture Tony Robinson (Jul 11)
- Re: Snort architecture Johnny Venter (Jul 11)