OISF brainstorming: planning phase 3 (take 3)
GEO IP Idea is to add a keyword that would be used to interact with GEOIP database (free at least) and be able to use it to detect things like control canal. For example, an IRC server in an non common country is certainly a control canal. Live ruleset swap A must have! This is vital for critical environnement. This is very costly in memory and this should be an option to avoid exploding low memory boxes. ...