[Snort-users] Not able to catch internal attacks

David Harris davidh at ...643...
Tue Oct 17 21:54:31 EDT 2000

I always thought one of the advantages of IDS systems were that they were
able to detect attacks coming from the internal network.  But with the way
the rules are set up this is not going to happen as most signatures are
based on "Outside -> Inside" or "Inside -> Outside" so its wont log any
"Inside -> Inside" attacks.

- David Harris

