Snort mailing list archives
about threshold
From: 강명훈 <mhkang589 () gmail com>
Date: Tue, 14 Jul 2015 23:38:54 +0900
Hi everyone. I have made rules below. alert udp any any -> 16x.12x.10x.2 53 (msg:"scan test"; threshold:type threshold, track by_src, count 1, seconds 2; classtype:TEST; sid:1999949;) alert udp any any -> 16x.12x.10x.2 53 (msg:"flood test"; threshold:type threshold, track by_dst, count 1, seconds 2; classtype:TEST; sid:1999950;) And i have tested by nslookup. It happened two packets(A, AAAA record) per one dns query. My expectation that happen two 'scan test' events. But it happened two 'scan test' events and two 'flood test' events. Why different rules matching the same packet? Is it normal? -- *kangmyounghun.blogspot.kr <http://kangmyounghun.blogspot.kr/>* *kr.linkedin.com/pub/myounghun-kang/74/238/93a* <http://kr.linkedin.com/pub/myounghun-kang/74/238/93a>
------------------------------------------------------------------------------ Don't Limit Your Business. Reach for the Cloud. GigeNET's Cloud Solutions provide you with the tools and support that you need to offload your IT needs and focus on growing your business. Configured For All Businesses. Start Your Cloud Today. https://www.gigenetcloud.com/
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-sigs http://www.snort.org Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- about threshold 강명훈 (Jul 14)