[Snort-sigs] UDP-storm snortsig?

Jonas Vreintaal Jonas.Vreintaal at ...1235...
Mon Jan 27 12:38:28 EST 2003


Due to the recent UDP packet storm this weekend, the portscanmodule in 
snort (snort-1.8.6) didn´t report anything.

Is there any easy snortrule or any way to configure the portscanmodule to 
detect massive UDP traffic?

Best Regards

---
Jonas Vreintaal
IT - Security
Karolinska Institutet
Tel: +4687286539
Cellular: +46703966539
  






More information about the Snort-sigs mailing list