Snort’s IP reputation preprocessor checks IP addresses against a blocklist and/or whitelist at the time packet headers are decoded. This preprocessor allows you to have a list of tens of thousands or more IP addresses that you can check against with minimal performance overhead. If you’re running hundreds of thousands of IP-only rules, the work necessary to enter the engine across potentially hundreds of millions of packets per second stacks up to the point that you end up chewing up all available system resources.”]
Source: https://blog.talosintelligence.com/2012/04/snort-performance-and-ip-only-rules.html