Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 4.27 How can I Up: 4 Rules and Alerts Previous: 4.25 After I add

4.26 Where do the distance and within keywords work from to modify content searches in rules?

The ``distance'' keyword gives you a relative offset from the end of the last match, so it basically acts as a wildcarding mechanism. You can also use the new ``within'' keyword to limit how deep into the packet from the end of the distance it'll search before it stops.



Nigel Houghton 2006-10-02