标签: snort denial-of-service
提醒tcp $ HOME_NET any - > $ HOME_NET 80(flags:S; msg:“可能的TCP DoS”;流程:无状态;阈值:键入both,跟踪by_src,计数70,秒10; sid:10001; rev:1;)
答案 0 :(得分:1)
请参阅链接:http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node35.html
实施例:
图片来源:http://kangmyounghun.blogspot.com/2017/01/snort-threshold.html