Snort mailing list archives
Syn-Flood
From: Frank Barton <pauling () starwolf biz>
Date: Wed, 12 Nov 2003 10:47:46 -0500
I've been looking for a rule that would detect a syn-flood. and the only way I can think of doing this would be with N "activate" rules (Where N is the number of SYN packets that arive in a specified time), and I think there's got to be a better way. after reading the rules for dos-attacks, all I saw was that each tool that is detected, is detected by some content string, not specifically by a volume. the documentation pdf doesn't have anything in it about a "count" option, or any other way that I can think of to count packets. if anybody has any ideas, I'd be most thankful. ob: snort --V: 2.0.0\ -- Frank Barton Starwolf.biz Systems Administrator www.starwolf.biz/~pauling (My Key is linked there.)
Attachment:
_bin
Description:
Current thread:
- Syn-Flood Frank Barton (Nov 12)
- Re: Syn-Flood Matt Kettler (Nov 12)
