[Discussion] Submitted Ideas
Matt Jonkman
jonkman at jonkmans.com
Wed Feb 4 19:33:10 UTC 2009
Martin Fong of SRI sent in a list of some very good ideas. I'll post
them below and lets discuss a bit. I'm sure Martin can add to it as we go.
- Content-based alert message substitution
- Non-combinatoric IP/port lists
- Cooperative event loops (e.g., libevent) to support asynch I/O
- On-the-fly rule updates without state loss
- Configuration file conditional preprocessor
- Variable blackboards
- Non-tokenized preprocessor parameter lines
Thanks Martin!
Matt
--
--------------------------------------------
Matthew Jonkman
Emerging Threats
Phone 765-429-0398
Fax 312-264-0205
http://www.emergingthreats.net
--------------------------------------------
PGP: http://www.jonkmans.com/mattjonkman.asc
More information about the Discussion
mailing list