Project

General

Profile

Actions

Feature #488

closed

IPS mode delayed rule initialization

Added by Victor Julien over 12 years ago. Updated about 12 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Now that live ruleswaps are supported, in IPS mode we can delay the rules init. Reason is to reduce the time that traffic is not flowing. As the traffic won't be inspected this behaviour needs to be optional.

Logic would be:
1. start IPS mode with empty ruleset
2. after init trigger a rule reload immediately

Complication: starting with an empty ruleset will make sure htp callbacks are not registered, which a ruleswap currently can't change.

Please create a high level design for discussion first.


Files


Subtasks 1 (0 open1 closed)

Feature #522: live rule reloads: support enabling/disabling libhtp callbacksClosedEric Leblond08/15/2012Actions
Actions

Also available in: Atom PDF