Sagan high stable other
[SONICWALL] Intrusion Detection - Possible SYN Flood
[SONICWALL] Intrusion Detection - Possible SYN Flood
Detection Logic
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[SONICWALL] Intrusion Detection - Possible SYN Flood"; content: "Possible SYN Flood"; pcre:"/src\:\s(\d+)(?<!10)\.(\d+)(?<!192\.168)(?<!172\.(1[6-9]
| 2\d
| 3[0-1]))\.(\d+)\.(\d+)/"; normalize; classtype: attempted-dos; parse_src_ip: 2; parse_dst_ip: 3; reference: url,www.sonicwall.com/downloads/SonicOS_Log_Event_Reference_Guide.pdf; sid:5002696; rev:5; metadata: updatedon, 2024_07_19;) Field Validations
Loading…
Comments (0)
Loading comments...