THC SSL DoS tool seeks to issue a Denial of Service (DoS) against hosts that offer SSL/TLS encrypted services. Using a single SSL connection to a server, thousands of SSL handshake renegotiation requests can be performed very quickly. Using the default configuration on Snort’s SSL preprocessor we were not going to see the renegotiation happening. The reason is that once a successful SSL connection is made, without an SSL decryption appliance (Sourcefire sells them), Snort will ignore the rest of the conversation – the logic being that, since it’s now encrypted, we can’t do any detection.”]
Source: https://blog.talosintelligence.com/2011/10/ssl-dos-snort-and-you.html

