Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 5.2 So do I Up: 5 Shared Object Rules Previous: 5 Shared Object Rules

5.1 Just what is an SO rule?

An SO rule is a loadable Snort module that can quickly extend the detection capabilities of Snort. We have added an API to the detection engine so that vulnerability researchers aren't restricted by the finite number of Snort keywords when writing rules. This also allows the rule writer to do some very complex things as they now have the full power of the C language at their disposal.



Nigel Houghton 2006-10-02