[Discussion] Submitted Ideas
    Matt Jonkman 
    jonkman at jonkmans.com
       
    Wed Feb  4 19:33:10 UTC 2009
    
    
  
Martin Fong of SRI sent in a list of some very good ideas. I'll post
them below and lets discuss a bit. I'm sure Martin can add to it as we go.
    - Content-based alert message substitution
    - Non-combinatoric IP/port lists
    - Cooperative event loops (e.g., libevent) to support asynch I/O
    - On-the-fly rule updates without state loss
    - Configuration file conditional preprocessor
    - Variable blackboards
    - Non-tokenized preprocessor parameter lines
Thanks Martin!
Matt
-- 
--------------------------------------------
Matthew Jonkman
Emerging Threats
Phone 765-429-0398
Fax 312-264-0205
http://www.emergingthreats.net
--------------------------------------------
PGP: http://www.jonkmans.com/mattjonkman.asc
    
    
More information about the Discussion
mailing list