|
|
Choosing A Webhost: |
Re: Rule Load Formula: msg#00075security.ids.snort.bleedingsnort
Yes, I've seen that site, but I was unsatisfied with having to rely on their results and with the lack of an API (for lack of a better term). It seems worth it to me to figure out exactly what it takes (perhaps down to count/size of memcpy's, etc?) for a rule op. Applications of this formula would be mainly in scripting to run historical reports on rule matches per system load. Or, more importantly for those of us who are always redlining our boxes, answering questions like "how many pps will I drop with the addition of this rule?" or "what is the rule capacity of this given setup?" I think the latter has been more of an issue lately, especially when you look at the exponential growth of the rule sets. Making truly informed decisions about the entirety of the rule set seems like a worthwhile endeavor. On 1/11/07, Matt Jonkman <jonkman-WwB1pFISwSkm7effSn6vN9HuzzzSOjJt@xxxxxxxxxxxxxxxx> wrote: Turbosnort.com is probably what you were thinking about. By the vigilant
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Rule Load Formula, Matt Jonkman |
|---|---|
| Next by Date: | Re: Rule Load Formula, Matt Jonkman |
| Previous by Thread: | Re: Rule Load Formula, Matt Jonkman |
| Next by Thread: | Re: Rule Load Formula, Matt Jonkman |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |