Snort mailing list archives

Dynamic Preprocessor- packets from established flows


From: Alex Adamos <alexthakidadam () hotmail com>
Date: Tue, 29 Jan 2013 22:01:53 +0200


Hi,
i managed to get my own preprocessor running (using DPX starter kit). I would like to know when a packet gets called by 
my preprocessor, whether it's from an established flow or not. Can anyone help me how to do this?
Also, i have a counter to the packets being processed by my DPX, and i see a significant difference with the other 
preprocessors. It's like my DPX doesn't get called for every packet.I add my preprocessor like this :
_dpd.addPreproc(DPX_Process, PRIORITY_LAST,PP_DPX,PROTO_BIT__TCP|PROTO_BIT__UDP);
thanks,Alex.                                      
------------------------------------------------------------------------------
Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS,
MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current
with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft
MVPs and experts. ON SALE this month only -- learn more at:
http://p.sf.net/sfu/learnnow-d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: