|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [Snort-users] Applying a rule on entire session
From: Dennis George (easyeinfo
yahoo.com)
Date: Wed Sep 08 2004 - 03:53:11 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hi,
>>flowbits and looking for the FIN and/or RST flags?
I mean to say that the rules should be applied to the reassembled data chunk of the entire session. The rule should not be applied to each packet coming.... instead after all the packet form a session then only apply that rule.........
Regards
Dennis
"Alex Butcher, ISC/ISYS" <Alex.Butcher
bristol.ac.uk> wrote:
--On 07 September 2004 20:48 -0700 Dennis George
wrote:
>
> Hi all,
>
> Is it possible to apply a particular rule only after catching the entire
> session, not on every packet............ ??
flowbits and looking for the FIN and/or RST flags?
> Thanks in advance........
> Dennis
Best Regards,
Alex.
--
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9
---------------------------------
Do you Yahoo!?
Yahoo! Mail - 50x more storage than other providers!
-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click
_______________________________________________
Snort-users mailing list
Snort-users
lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]