Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: within Up: distance Previous: Format   Contents

Example

The rule listed in Figure [*] maps to a regular expression of /ABCDE.{1}EFGH/.

Figure: distance usage example
\begin{figure}\begin{verbatim}alert tcp any any -> any any (content:''ABC''; content: ''DEF''; distance:1;)\end{verbatim}
\end{figure}



Steven Sturges 2007-10-04