[Bro] Connection dictionaries

Vern Paxson vern at icir.org
Tue Apr 24 13:36:16 PDT 2007


> Is there a specific reason (apart from performance
> maybe?) for going with this approach rather than creating a single
> dictionary indexed by a 5-tuple, 5th-tuple being the protocol?

That structure arose due to how the code evolved.  Using 4-tuples instead
of 5-tuples saves a small amount of memory, too.

		Vern



More information about the Bro mailing list