How can i convert Snort rules to BRO ?


Bro ships with a script snort2bro but is it somewhat outdated and
does not support some of the newer Snort options.


is there any better solution? Can i just rely on Bro policies? will that be enough? is there a real difference betwen the snort rules and Bro policies?

Robin Sommer wrote:

Well, the systems' detection approaches are quite different. Bro
does not primarily rely on pattern matching as Snort does; its
policies use a different abstraction. You can't really compare the