Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 4.22 Can Snort trigger Up: 4 Rules and Alerts Previous: 4.20 What is the

4.21 Are rule keywords ORed or ANDed together?

>From Section 2.1 of the Snort Manual:

All of the elements in that make up a rule must be true for the indicated rule action to be taken. When taken together, the elements can be considered to form a logical AND statement. At the same time, the various rules in a Snort rules library file can be considered to form a large logical OR statement.