A preprocessor and a detection-plugin for Snort. The former calculates a set of features from network traffic, in the KDD (Knowledge Discovery Database) fashion; the latter adds the capability to understand rules extrapolated from features by means of mac