On 26.02.2016 06:58:23, Crawford, David wrote:
>
> What if I want to search by CIDR ranges? Now every IPv4 field has to
> be pulled from the DB, one by one, de-fanged and compared at the
> application layer where I’ve lost any efficiencies of the database
> engine. The same applies for domains or URLs; if I want to search by
> wildcard, or regex patterns every indicator has to be pulled into
> the application layer de-fanged, compared, etc., etc.
>
Excellent point, David.
--
Cheers,
Trey
--
Trey Darley
Senior Security Engineer
4DAA 0A88 34BC 27C9 FD2B A97E D3C6 5C74 0FB7 E430
Soltra | An FS-ISAC & DTCC Company
www.soltra.com
--
"No matter how hard you try, you can't make a baby in much less than 9
months. Trying to speed this up *might* make it slower, but it won't
make it happen any quicker." --RFC 1925