jnebrera at eneotecnologia
Feb 1, 2012, 11:11 PM
Post #3 of 3
> we removed this code as it was strict so not too many different filter
> types could not be accommodated as many people want. If you go back with
> releases in SVN you should find the code
Well, you are right many filtering conditions cant be meet, but for
some particular tasks goes quite well.
We are developing some enhancements on Snort and in order to speed
the Aho Corasick side we are preceeding it with a combination of several
filters, one of them based on Blooms.
The first prototype shows no missed alerts and just <10% false
positive (that later on discards AC) but we are not seeing real
I believe the reason is that as first prototype, the implementation
of the prefiltering functions is still a bit crappy :D Thats why we want
to look into your code.
May I ask what version still contained the bloom filtering stuff?
Jaime Nebrera - jnebrera [at] eneotecnologia
Consultor TI - ENEO Tecnologia SL
C/ Manufactura 2, Edificio Euro, Oficina 3N
Mairena del Aljarafe - 41927 - Sevilla
Telf.- 955 60 11 60 / 619 04 55 18
Ntop-misc mailing list
Ntop-misc [at] listgateway