Summary
Since DCE/RPC is increasingly becoming an attack vector, the role of DCE/RPC analysis is a key component of Snort. In this chapter, we discussed the DCE/RPC protocol and the Snort inspectors related to DCE/RPC. We discussed briefly the workings of the protocol, as well as connection-oriented and connectionless DCE/RPC. We also covered the different inspectors as well as the related configuration.
In the next chapter, we will discuss the topic of IP reputation in an IDS and the IP reputation inspector in Snort 3.