[ Thanks to Jan
Stafford for this link. ]
“What capabilities does Snort have that might surprise
or be underused by IT managers?“Angela Orebaugh: Snort has some powerful
functionality built into the pre-processors. These include the
ability to maintain state, fragmented packet reassembly, stream
reassembly, HTTP normalization, application decoders, portscan
detectors and performance monitoring…”