Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Types of Snort Rules- For the rules in this section, determine the typeof rule, the Sort configlocationwhere you would find the rule (/etc/nsm/rules, threshold.conf, etc),

Types of Snort Rules- For the rules in this section, determine the typeof rule, the Sort configlocationwhere you would find the rule (/etc/nsm/rules, threshold.conf, etc), and describe what the rule does.

5) alerttcp$EXTERNAL_NET any -> $SQL_SERVERS 1433 (msg:"SQLSA BFL";content:"[02]"; content:"sa";depth:2;offset:39;nocase;reference:bugtraq,4797;reference:nessus,10673;sid:3542;rev:7;)

6) alerttcp$HOME_NET any -> $EXTERNAL_NET 5222 (msg:"GPL CHATMISCTraffic"; flow:to_server, established; content:"nocase;reference:url,www.google.com/talk;classtype:policy-violation;sid:1000000230; rev:2;)

7) event_filter gen_id 1,sig_id 2002949, type limit, track by_src, count 1, seconds 300

8) suppress gen_id 2,sig_id 1001001, track by_src,ip10.1.2.252

9)alerttcp$EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET Scan";flow:to_server,established: content:"User-Agent|3a|sqlmap"; fast_pattern:only;http_header; detection_filter:track by_dst,count 4, seconds 20;reference:url,sqlmap.sourceforege.net;sid:2008538;rev:8;)

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Data Communications and Networking

Authors: Behrouz A. Forouzan

5th edition

73376221, 978-0073376226

More Books

Students also viewed these Computer Network questions