nzymedefense / nzyme

Network Defense System.
https://www.nzyme.org/
Other
1.42k stars 145 forks source link

Limit amount of data taggers are looking at #1057

Closed lennartkoopmann closed 3 months ago

lennartkoopmann commented 5 months ago

We can easily end up with giant TCP sessions. Drastically limit what amount of data is being scanned, based on tagger requirements.

Some taggers that look at the first bytes of a session also do not need to re-visit it at all.