Detection Engine

Jallam Amada <[email protected]>
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <[email protected]>
Hello Guys,

i have a question regarding packet evaluation in Snort 2.9.11 (not
C++!). I am willing to replace the Detection Engine (no portgroups, no
fpPatternMatching...) by simply running my own function to the flowing
packet while ignoring the rest of Snort. As simple as it might sound,
what is the fastest way to achieve this with existing function in the
framework?

I don't need any preprocessors or anything, i just need to make use of a
firewall-functionality in Snort (packet classification).


Thank You..

Jallam Amada

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.