Snort mailing list archives

Re: not detecting common intrusion


From: Erek Adams <erek () theadamsfamily net>
Date: Wed, 26 Jun 2002 17:24:18 -0700 (PDT)

On Wed, 26 Jun 2002, Cearns Angela wrote:

Thanks Erek

:)  No problem.

Pardon my ignorance, but if snort doesn't detect
"bandwidth consumption" attacks - floods, what do the
"dos.rules" and "ddos.rules" included in the
snort.conf file detect? (May be I should learn to read
the rules files better)...

It's not ignorance, it's just something you haven't "learned" yet. :)

I'd say 90% of the rules in (d)dos.rules are simply matching for known
patterns of the (d)dos attacks.  IOW, when you fire off dos type fred, there
is a specific pattern of bits associated with the fred attack.

Try to keep in mind how snort works.  Frame comes over the wire, pcap brings
it into snort, snort looks at the frame and makes some decisions based on it.
Now granted, that's oversimplified, but that's the gist of it.

The snort.org website has some good technical docs on how/what's going on
under the hood.  If you're really interested, that's where you might want to
pursuse reading a bit more.

Cheers!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net



-------------------------------------------------------
This sf.net email is sponsored by: Jabber Inc.
Don't miss the IM event of the season | Special offer for OSDN members! 
JabberConf 2002, Aug. 20-22, Keystone, CO http://www.jabberconf.com/osdn
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: