From: Nathaniel H. <nat...@gm...> - 2004-09-08 20:07:17
|
This quote from Snort 2.0 Intrusion Detection by Brain Caswell published by syngress leads me to believe that there is such a thing as acquisition plugins: "The Snort 2.0 architecture allows for what are called 'acquisition plug-ins.' These plug-ins allow a developer to write a specific packet-capture network card driver for a particular operating system (Linux), and this plug-in would provide Snort with packet capture at much higher speeds." I'm interested in "much higher speeds" such as 350MB+ does anyone have any information on these plugins such as where to get them or how to start developing such a plugin? Thanks, Nate |