|
|
|
|
Snort Forums Archive
Archive Home » Snort Development » Detection Engine Architecture
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
Detection Engine Architecture
Posted by TheMadHatter on March 04, 2006 15:09:59
Hello everyone,
I am currently at university and am writing my final year dissertation, part of which involves analyzing Snort. I have read Martin Roesch's paper from LISA '99 and am using that as a basis for much of my analysis.
My question to the experts is: Does anyone know if Snort's Detection Engine still uses the linked list structure detailed in Roesch's paper (Figure 3, pp231) to store the rule chain? If so, is it a basic linked list, i.e. can only be traversed one-way?
Thanks to anyone who can help on this matter!
Scott. |
|
|
|
|
|