Next: ASN.1 Keywords
Up: Preprocessors
Previous: Examples/Default Configuration from snort.conf
Contents
ASN.1 Detection
The asn.1 detection plugin decodes a packet or a portion of a packet, and looks
for various malicious encodings.
The general configuration of the asn.1 rule option is as follows:
asn1: [keyword [argument]], . . .
Multiple keywords can be used in an 'asn1' option and the implied logic is
boolean OR. So if any of the arguments evaluate as true, the whole option
evaluates as true.
Subsections
Steven Sturges
2006-12-08
|