Snort IDS and IPS Toolkit — Featuring Jay Beale and Members of the Snort Team

Snort is an incredible piece of code, but the engine is only a part of what makes Snort such a useful tool. The rules are the real meat of what we all work with from day to day and from vulnerability to vulnerability. In this chapter, we'll discuss how to write Snort rules. You may be very interested to learn some of the nonsecurityrelated things Snort can do for you!
Rules can be fun (you don't hear that very often, eh?). But they can also inhibit you and tell you what you can't do, when you've had enough fun, and what kinds of fun will buy you prison time. Those rules are not fun, and they're not the rules we are going to learn about in this chapter.
Here we're going to look at Snort rules or signatures, often referred to as simply rules (the terms are interchangeable in this context). At an abstract level, a rule is a way to describe a condition or state on a network. We have many adjectives at our disposal in the Snort rules language, from very basic to extremely complex, and nearly every combination in between. If you consider the way we would use language to describe a mundane act, you may more easily understand the concepts behind writing your own rules.
Consider the following instruction:
If a blue hummingbird approaches the hummingbird feeder in the front yard (not the bird feeder) please get the camera...