|
|||||||||||
|
RE: Detecting Connections in Snort
From: Faiz Ahmad Shuja <faizshuja(at)yahoo.it>
Date: Mon Jun 02 2003 - 11:34:39 EDT
currently the format is: portscan: <monitor network> <number of ports> <detection period> <file path> it should be something like: portscan: <monitor network> <number of connections> <dst port> <detection period> <file path> Though, this preprocessor has capability that alerts would only show once per scan, rather than once for each packet. So it can be modified for specific number of connection threshold for single alert. Is this possible?
Regards,
-----Original Message-----
I understand that exists a particular funcionality in portscan snort's preprocessor, which let you set a threshold for connections. You can find more information en Snort 2.0 book (Syngress). Bye
Marcelo
Faiz Ahmad Shuja wrote: >Does anybody have idea about detecting multiple connections from a
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:12 EDT |
||||||||||
|
|||||||||||