Phase 2 development is almost over now. Among the completed major features:
- Multithread
- protocol discovery
- smb logging
- HTTP logging
- flowvars
One of the advantage of Suricata over Snort is protocol discovery combined to HTTP parsing by libhtp. It provides a huge improvement over Snort as a lot of bad flow are using HTTP on non standard ports.