    I am a student of Telecommunications and Electronics, in the last year of the University, in Cuba, I am doing research on intrusion detection in the data link layer, let me know if there is a rule in Snort linked with the Ethernet frame or packet , to detect any abnormal behavior. Also know if someone ventured into the issue, if some rule craer tried over Ethernet. Any help you can give me will always be good.

