Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Third Party Tools » Converting snort rules to packet streams

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Converting snort rules to packet streams


Posted by bromer on June 12, 2005 12:04:42

Hi

I was wondering if there is a tool to generate a packet stream that will surely set of at predefined number of alerts? I have an assignment to perform a performence-test on Snort. I'm sure I could write the tool myself in C but I havn't got the time..

If the tool dosn't exists I would like to know if there is any other tool to generate attacks...


Posted by bwilson on July 28, 2005 11:24:51

I too have a simular testing requirement. My initial investigation was to look for an old 'Defcon' "Capture the Flag" competition data. Although repeatable, it may not provide an optimum test packet stream. Worse, google results are showing too many '404' hits when I try to get a copy.

If worse comes to worse, I'll have to write my own but I figured the first step was to ask.

Thanks,
Bob Wilson