hi there
How can i convert Snort rules to BRO ?
regards,
Jules
hi there
How can i convert Snort rules to BRO ?
regards,
Jules
Bro ships with a script snort2bro but is it somewhat outdated and
does not support some of the newer Snort options.
Robin
Thanks Robin
is there any better solution? Can i just rely on Bro policies? will that be enough? is there a real difference betwen the snort rules and Bro policies?
Robin Sommer wrote:
Well, the systems' detection approaches are quite different. Bro
does not primarily rely on pattern matching as Snort does; its
policies use a different abstraction. You can't really compare the
two.
Robin