Does anybody have idea about detecting multiple connections from a single IP in Snort?. I want to detect multiple connection request from a single IP to mail server [port 25]. Somtimes a single IP have taken up all the connection slots. Is there anyway to set a threshold?. If I am getting multiple connections from a single host to any service and it reaches a specific count, I get the alert?.
Please advise.
Thanks!
Regards, Faiz
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:12 EDT