You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Protocol detection implementation in Suricata<br />
Based on fixed strings currently, e.g. "GET " for HTTP<br />
"probing parser" parses protocol to verify<br />
then hands off TCP connection to real parser<br />
Protocol detection runs on top of TCP stream reasssembly<br />
Éric Leblond, Victor Julien (OISF) <strong>The</strong> <strong>menace</strong> <strong>came</strong> <strong>from</strong> <strong>below</strong> <strong>Hack</strong>.<strong>lu</strong> 2012 52 / 66