Sagan high stable other

[SONICWALL] Intrusion Detection - Possible FIN Flood

[SONICWALL] Intrusion Detection - Possible FIN Flood

View Source

Detection Logic

alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[SONICWALL] Intrusion Detection - Possible FIN Flood"; content: "FIN Flood Blacklist on"; normalize; classtype: attempted-dos; parse_src_ip: 1; parse_dst_ip: 2; reference: url,www.sonicwall.com/downloads/SonicOS_Log_Event_Reference_Guide.pdf; sid:5002658; rev:3;)

Field Validations

Loading…

Comments (0)

Loading comments...