What would you guys look for in an intrusion prevention system?
Pharos's current features:
1) Invalid TCP flag combination checking
2) Regexp system for payload checking
3) Regular payload checking (byte-for-byte checking)
4) Logging of malicious packets
5) TCP checking only
Possible upcoming features:
1) A config option to write packet contents (including headers) to a file
2) UDP checking (100% possible)
3) ICMP checking (100% possible)
4) Ability to email errors/logs
Is there anything else you guys would like? Is there anything that should be taken out?
If you guys want to help out, I'd love the help
