Adds fuzzyHash operator

The fuzzyHash operator can be used to match files. In conjuntcion
with FILES_TMP_CONTENT collection it can scan uploaded files and
try to match it with a pre caculated list of know malicious content,
more details on how it works can be found on ssdeep website:
http://ssdeep.sourceforge.net/
This commit is contained in:
Felipe Zimmerle
2013-12-06 09:24:42 -08:00
parent 873c628b1a
commit 96865a92d3
4 changed files with 180 additions and 0 deletions

View File

@@ -159,4 +159,6 @@ int DSOLOCAL tree_contains_ip(apr_pool_t *mp, TreeRoot *rtree,
int DSOLOCAL ip_tree_from_param(apr_pool_t *pool,
char *param, TreeRoot **rtree, char **error_msg);
int read_line(char *buff, int size, FILE *fp);
#endif