Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Detecting Connections in Snort

From: Faiz Ahmad Shuja <faizshuja(at)yahoo.it>
Date: Mon Jun 02 2003 - 11:34:39 EDT


Snort's portscan processor works on TCP connection attempts to more than P ports in T seconds or UDP packets sent to more than P ports in T seconds. It doesn't work for number of C connections to P destination port in T seconds.

currently the format is:

portscan: <monitor network> <number of ports> <detection period> <file path>

it should be something like:

portscan: <monitor network> <number of connections> <dst port> <detection period> <file path>

Though, this preprocessor has capability that alerts would only show once per scan, rather than once for each packet. So it can be modified for specific number of connection threshold for single alert.

Is this possible?

Regards,
Faiz

Do you need help?X

-----Original Message-----
From: Marcelo Olguin [mailto:molguin@inf.utfsm.cl] Sent: Monday, June 02, 2003 7:38 PM
To: Faiz Ahmad Shuja; focus-ids@securityfocus.com Subject: Re: Detecting Connections in Snort

I understand that exists a particular funcionality in portscan snort's preprocessor, which let you set a threshold for connections. You can find more information en Snort 2.0 book (Syngress).

Bye

Marcelo
-.-

Faiz Ahmad Shuja wrote:

>Does anybody have idea about detecting multiple connections from a

  • application/x-pkcs7-signature attachment: smime.p7s
Received on Mon Jun 2 21:06:26 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:12 EDT

Do you need more help?X

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library