Translating Snort rules to STATL scenarios
Steven T. Eckmann · 2001
that they include signatures for some collection of known attacks, and monitor an event stream looking for instances of any signature in their collection. There is an enormous duplication of effort within the IDS community, as each newly discovered attack requires independent specification for each IDS. Sharing of signature collections has obvious Snort is an IDS with a large published collection of signatures. This paper considers automated translation of Snort rules to STATL scenarios. Automatically translating Snort rules to STATL scenarios has the practical effect of allowing the use of Snort's large signature collection with NetSTAT sensors, with essentially no new work as new Snort signatures are developed.