[Snort-sigs] UDP-storm snortsig?

Jonas Vreintaal Jonas.Vreintaal at ...1235...
Mon Jan 27 12:38:28 EST 2003

Due to the recent UDP packet storm this weekend, the portscanmodule in 
snort (snort-1.8.6) didn´t report anything.

Is there any easy snortrule or any way to configure the portscanmodule to 
detect massive UDP traffic?

Best Regards

Jonas Vreintaal
IT - Security
Karolinska Institutet
Tel: +4687286539
Cellular: +46703966539

More information about the Snort-sigs mailing list