Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: ASN.1 Keywords Up: Preprocessors Previous: Examples/Default Configuration from snort.conf   Contents


ASN.1 Detection

The asn.1 detection plugin decodes a packet or a portion of a packet, and looks for various malicious encodings.

The general configuration of the asn.1 rule option is as follows:

asn1: [keyword [argument]], . . .

Multiple keywords can be used in an 'asn1' option and the implied logic is boolean OR. So if any of the arguments evaluate as true, the whole option evaluates as true.



Subsections

Steven Sturges 2006-12-08