Research On TCP reassembly in Snort IDS

Ming Yu Fan · China Information Security · 2007

Base on the study on the source code of Snort, analyze the principle and implementation of TCP assembly in Snort IDS, present related data structures and arithmetic. Introduce attacks that towards TCP assembly module and the protection methods Snort adopted. Indicate several weaknesses of TCP assembly and some new research fields of it.

Read the paper · More papers on PaperTik