Summary
In this chapter, we looked at the HTTP inspector, which is one of the key modules of Snort 3. We briefly discussed HTTP and also looked at the function of the inspector. We built up the necessary background to understand how the various HTTP-related keywords would work from a Snort rule-writing perspective. Finally, we looked briefly at a few configuration parameters.
In the next chapter, we will discuss the SMB and DCE RPC protocols, their usage, and how the DCERPC inspector analyzes these protocols.