
jnebrera at eneotecnologia
Feb 1, 2012, 11:11 PM
Post #3 of 3
(292 views)
Permalink
|
Hi Luca, > we removed this code as it was strict so not too many different filter > types could not be accommodated as many people want. If you go back with > releases in SVN you should find the code Well, you are right many filtering conditions cant be meet, but for some particular tasks goes quite well. We are developing some enhancements on Snort and in order to speed the Aho Corasick side we are preceeding it with a combination of several filters, one of them based on Blooms. The first prototype shows no missed alerts and just <10% false positive (that later on discards AC) but we are not seeing real performance gain. I believe the reason is that as first prototype, the implementation of the prefiltering functions is still a bit crappy :D Thats why we want to look into your code. May I ask what version still contained the bloom filtering stuff? -- Jaime Nebrera - jnebrera [at] eneotecnologia Consultor TI - ENEO Tecnologia SL C/ Manufactura 2, Edificio Euro, Oficina 3N Mairena del Aljarafe - 41927 - Sevilla Telf.- 955 60 11 60 / 619 04 55 18 _______________________________________________ Ntop-misc mailing list Ntop-misc [at] listgateway http://listgateway.unipi.it/mailman/listinfo/ntop-misc
|