Snort mailing list archives

Re: basic understanding questions


From: amir levinzon <amir.h.univ () gmail com>
Date: Tue, 16 Sep 2014 23:47:16 +0300

lol p-;

unfortunately it's not...i'm actually computer science graduate (from 2
weeks ago)
i'm working for a professor in the uni(dosn't matter who) and we are trying
to write something similar to snort but much smaller in code.
and since we both do'nt know the software to well and he got a lot of other
thing and i don't so its my job to understand the things and to come with
answers....

now can i ge some answers pretty please?

the first questions was in order to take small group of rules and to be
sure that "standart" web user will get some allers.

the second questions is in order to get small idea regarding how the parser
works,Of course I looked at the open source parser but i need to write
something much smaller(snort parser is about 9000 code line....to
complicated)  i thought about using red - black tree  or AVL or even Bloom
filter for the decision it delfe and for thr preprocessing....


A simple answer will be great.... i'm searching almost for a month....

TNX Amir
------------------------------------------------------------------------------
Want excitement?
Manually upgrade your production database.
When you want reliability, choose Perforce.
Perforce version control. Predictably reliable.
http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: