Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Format Up: Payload Detection Rule Options Previous: Format   Contents


distance

The distance keyword allows the rule writer to specify how far into a packet Snort should ignore before starting to search for the specified pattern relative to the end of the previous pattern match.

This can be thought of as exactly the same thing as depth (See Section [*]), except it is relative to the end of the last pattern match instead of the beginning of the packet.



Subsections

Steven Sturges 2006-12-08