Dear all,
We would like to use Bro as an IPS, which reads packets from
netfilter, ipfw, or something like that, and may drop packets when
some conditions are met. Somebody refers to an old presentation at
Bro workshop 2007, but the link has been broken. Is there any ready-to-use
solution for this purpose, or should we resort to modifying the source code?
Any suggestion is appreciated.
Po-Ching