Re: Machine Learning preprocessor for Snort

"Carter Waxman \(cwaxman\) via Snort-devel" <[email protected]> Tue, 14 Aug 2018 14:34:57 +0000
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <[email protected]>
Might I suggest trying to build this as an inspector in Snort 3? Plugin development is far simpler:

Define a Module subclass – This defines your configuration.
Define an Inspector subclass – This runs your packet processing code
Define the InspectApi – This provides the loading hooks and define what you want delivered to the Inspector and how
Build against your Snort 3 installation
Drop the .so in your dynamic plugin folder and run

Take a look at the README and some of the examples in the snort_extra tarball. src/inspectors/dpx would be a good start.

-Carter

From: Snort-devel <[email protected]> on behalf of Hossein Torbat via Snort-devel <[email protected]>
Reply-To: Hossein Torbat <[email protected]>
Date: Tuesday, August 14, 2018 at 8:07 AM
To: "[email protected]" <[email protected]>
Subject: [Snort-devel] Machine Learning preprocessor for Snort

We are trying to integrate our Machine Learning traffic detection algorithm (written in python) to snort as a preprocessor component, but as we are new to snort, I want to know if there were any previous effort for adding a similar algorithm to snort, or are there any guide which can help us to develop this faster.

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!