Ethereal-dev: [Ethereal-dev] heuristics using l7-filter?

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Thomas Anders <thomas.anders@xxxxxxxxxxxxx>
Date: Sun, 26 Feb 2006 00:47:33 +0100
With the move towards new-style dissectors there always seems to be a common problem of coming up with good heuristics to tell from a few bytes whether the chunk is likely the protocol in question (or not).

Is there a good reason to reinvent the wheel here and *not* consider using existing pattern definitions like those of e.g. the l7-filter project (http://l7-filter.sourceforge.net/technicaldetails)?


Just an idea,
+Thomas

--
Thomas Anders (thomas.anders at blue-cable.de)