Snort mailing list archives
Re: PCRE and cross packet matching
From: Joel Esler <jesler () sourcefire com>
Date: Mon, 6 Aug 2012 11:57:12 -0400
On Aug 6, 2012, at 9:36 AM, Joel Esler <jesler () sourcefire com> wrote:
BTW, if there are no "stream-based" equivalent to such keywords due to resource/complexity issues, how about creating keywords explicitly for the first packet of a stream - that is probably 99% of the problem area?
Also, just as an addendum, sorry for not posting it originally. We do have a keyword upcoming in a future version of Snort that ensures that you are at the start of a stream, no matter what. -- Joel Esler Senior Research Engineer, VRT OpenSource Community Manager Sourcefire
------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- PCRE and cross packet matching vpiserchia () gmail com (Aug 03)
- Re: PCRE and cross packet matching Patrick Mullen (Aug 03)
- Re: PCRE and cross packet matching Tony Robinson (Aug 03)
- Re: PCRE and cross packet matching Marcos Rodriguez (Aug 03)
- Re: PCRE and cross packet matching Jason Haar (Aug 05)
- Re: PCRE and cross packet matching Joel Esler (Aug 06)
- Re: PCRE and cross packet matching Joel Esler (Aug 06)
- Re: PCRE and cross packet matching vpiserchia () gmail com (Aug 06)