Snort mailing list archives

Re: Adding a new preprocessor in SNORT


From: Russ <rucombs () cisco com>
Date: Thu, 30 Jul 2015 16:18:49 -0400

You should also consider using Snort++. It is substantially easier to add a new inspector. Check the extra folder for an example. And let us know if you need any help.

Russ

On 7/30/15 10:10 AM, Al Lewis (allewi) wrote:

Hello:

There are examples in the source code and in the manual:

http://manual.snort.org/node40.html

Albert Lewis

QA Software Engineer

SOURCE*fire*, Inc. now part of *Cisco*

9780 Patuxent Woods Drive
Columbia, MD 21046

Phone: (office) 443.430.7112

Email: allewi () cisco com

*From:*basant subba [mailto:basantsubba () gmail com]
*Sent:* Thursday, July 30, 2015 9:45 AM
*To:* snort-users () lists sourceforge net
*Subject:* [Snort-users] Adding a new preprocessor in SNORT

I want to build a |Hybrid IDS| using open source tool |SNORT|. I read few good papers on that. But still I am not able to get a lead on how to mount |PHAD| (an anomaly based IDS) as a preprocessor to |SNORT. In general how would one add a new preprocessor in a SNORT? Any help would be highly appreciated.|



------------------------------------------------------------------------------


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: