Snort 2.0 Intrusion Detection

Snort has two preprocessor plug-ins that assist rule matching by combining data spread across multiple packets:
stream4
frag2
Both stream4 and frag2 are covered in additional detail in the sections that follow.
stream4, contained in spp_stream4.c, was announced in 2001 by Marty Roesch to improve Snort's handling of TCP sessions for selected traffic.
| Oink! | Snort's own FAQ discusses stream4 by quoting Marty Roesch's introductory announcement that announcement is not just historically useful, it gives hard detail on what the plug-in does. |
At the time, as quoted in www.snort.org/docs/faq.html#3.14, Martin wrote:
" I implemented stream4 out of the desire to have more robust stream reassembly capabilities and the desire to defeat the latest "stateless attacks" that have been coming out against Snort (c.f. stick and snot). stream4 is written with the intent to let Snort be able to handle performing stream reassembly for "enterprise class" users, people who need to track and reassemble more than 256 streams simultaneously. I've optimized the code fairly extensively to be robust, stable, and fast. The testing and calculations I've performed lead me to be fairly confident that stream4 can provide full stream reassembly for several thousand simultaneous connections and stateful inspection for upwards of 64,000 simultaneous sessions ".
stream4 has two goals, which we'll now explore:
TCP statefulness
Session reassembly
To understand what statefulness is, we need to review the TCP protocol. TCP introduces the concept of a "session" to Internet communications. A session has a clear beginning...