[Snort-sigs] DDOS rules (taqwa ahmed)

Alex McDonnell amcdonnell at sourcefire.com
Tue Feb 13 12:03:39 EST 2018


Generally speaking you want to use your firewall to protect yourself
against DDoS, Snort is not a great tool for this because it has to inspect
every packet for your DDoS conditions. That being said, I assume this is
more of a theoretical question, so what is the DDoS attack type you are
trying to mitigate?

Alex

On Tue, Feb 13, 2018 at 12:00 PM, <snort-sigs-request at lists.snort.org>
wrote:

> Send Snort-sigs mailing list submissions to
>         snort-sigs at lists.snort.org
>
> To subscribe or unsubscribe via the World Wide Web, visit
>         https://lists.snort.org/mailman/listinfo/snort-sigs
> or, via email, send a message with subject or body 'help' to
>         snort-sigs-request at lists.snort.org
>
> You can reach the person managing the list at
>         snort-sigs-owner at lists.snort.org
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Snort-sigs digest..."
>
>
> Today's Topics:
>
>    1. DDOS rules (taqwa ahmed)
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Tue, 13 Feb 2018 08:03:38 +0000
> From: taqwa ahmed <taqwa-315 at hotmail.com>
> To: "snort-sigs at lists.snort.org" <snort-sigs at lists.snort.org>
> Subject: [Snort-sigs] DDOS rules
> Message-ID:
>         <DB6PR0902MB181307461DA53153642D81C6A7F60 at DB6PR0902MB1813.
> eurprd09.prod.outlook.com>
>
> Content-Type: text/plain; charset="iso-8859-1"
>
>  Dear All,
>
> I'm new in snort  and  I would like to create rules to detect DDOS attacks
> .
>
> Kindly any help will be very appreciated .
>
>
> Thanks in advance,
>
> Taqwa
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL: <https://lists.snort.org/pipermail/snort-sigs/
> attachments/20180213/deed0a58/attachment-0001.html>
>
> ------------------------------
>
> Subject: Digest Footer
>
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs at lists.snort.org
> https://lists.snort.org/mailman/listinfo/snort-sigs
> http://www.snort.org
>
> Please follow these rules: https://snort.org/faq/what-is-
> the-mailing-list-etiquette
>
> Please visit http://blog.snort.org for the latest news about Snort!
>
>
> ------------------------------
>
> End of Snort-sigs Digest, Vol 9, Issue 11
> *****************************************
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20180213/dc424c42/attachment.html>


More information about the Snort-sigs mailing list