Victor Julien
Results
3
comments of
Victor Julien
If we implement this in Suricata it may also be useful: https://redmine.openinfosecfoundation.org/issues/1879
I think I would prefer a combination of per connection and global tracking. I think the per connection tracking is logic that needs to be in libhtp, as each allocation...
I would want it to be a real-time hard limit. This is how we keep limits for other subsystems in Suricata as well. Pretty much the allocation functions just return...