Reputation: 1547
I know how to configure and run snort with dynamic rules written.
I know some stages of processing like decoding, preprocessors, dynamic rules match, output plugins etc.
I am using snort as inline mode. I want to know full flow of processing from packet comes to snort and to packet is delivered to application.
Can any one suggest me a link like its complete flow description?
Thanks
Upvotes: 1
Views: 1161
Reputation: 6973
Slide 9 on this presentation http://www.slideshare.net/mboman/snort gives some information and page 45 in this pdf http://www.pearsonhighered.com/assets/hip/us/hip_us_pearsonhighered/samplechapter/157870281X.pdf should also help.
Upvotes: 2