【问题标题】:Configuring rules to detect SMTP, HTTP and DNS traffic配置规则以检测 SMTP、HTTP 和 DNS 流量
【发布时间】:2019-12-17 19:51:33
【问题描述】:

我目前正在尝试配置 Snort 规则以检测 SMTP、HTTP 和 DNS 流量。这个设置正确吗?

alert icmp any any -> $HOME_NET any (msg: "ICMP connection attempt"; sid:100000$
alert tcp any any -> $HOME_NET 80 (msg:"HTTP connection attempt"; sid:1000003; $
alert udp any any -> 10.8.9.39 any (msg: "DNS connection attempt"; sid:1000004;$
alert tcp $SMTP_SERVERS any -> $HOME_NET any (msg:"SMTP connection attempt"; si$

【问题讨论】:

    标签: networking sysadmin snort


    【解决方案1】:

    这些规则最终是正确的。可以在以下位置找到文档:https://www.snort.org/documents

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2021-07-26
      • 2018-12-20
      • 2020-01-30
      • 2021-09-11
      • 1970-01-01
      • 2021-06-26
      相关资源
      最近更新 更多