Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

1 . Write snort rules for the following requirements ( one rule per requirement ) : a . Generate an alert on TCP comms. ,

1. Write snort rules for the following requirements (one rule per requirement):
a. Generate an alert on TCP comms. ,from any source IP and port to any destination IP on port 443. The alert should display the following message: SSL/TLS communications to a port. You can use the following SID: 51500516
b. Generate an alert on IP comms. From any source IP and port to the following destination IP: 41.72.33.103 on any port. The alert should display the following message: Connection attempts to Cobalt strike C2 server. You can use the following SID: 51500517

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Advances In Knowledge Discovery In Databases

Authors: Animesh Adhikari, Jhimli Adhikari

1st Edition

3319132121, 9783319132129

More Books

Students also viewed these Databases questions

Question

What is Change Control and how does it operate?

Answered: 1 week ago

Question

How do Data Requirements relate to Functional Requirements?

Answered: 1 week ago