[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Splitting up snort



Hi,

'snort' is a network intrusion detection system. Apart from the binary and
the 'standard' config files, there are some configfile 'libraries'
(currently in /etc/snort), containing attack patterns to scan the network
for.
I think /etc/snort is not the correct place to have these attack patterns,
and i'd like to move these to /var/lib/snort. 
Then i'd like to split snort up in a 'snort' package, and a 'snort-patterns'
package, the second containing the attack pattern files, to allow people to
install newer versions of the attack patterns, made available in a .deb, so
the complete package doesn't need upgrading, when the pattern files change.
This would allow 'unstable'-users to keep up with the rulefiles, and
'stable'-users to install a new ('unstable') pattern library.

Would /var/lib/snort be a correct location for these patterns ?
Can a package contain only 'configuration' files ?

Greets,
	Robert
-- 
			      Linux Generation
	"You must have an IQ of at least half a million."  -- Popeye



Reply to: