[Snort-users] rule to detect maximum duration of a connection

Brian Lavender brian at ...14200...
Mon Mar 29 16:36:53 EDT 2010


Is it possible to write a rule that will detect the duration of a TCP
connection? Say I have a port and I want to warn when the TCP connection
has exceeded 10 seconds.

TCP connections of course.

brian
-- 
Brian Lavender
http://www.brie.com/brian/

"There are two ways of constructing a software design. One way is to
make it so simple that there are obviously no deficiencies. And the other
way is to make it so complicated that there are no obvious deficiencies."

Professor C. A. R. Hoare
The 1980 Turing award lecture




More information about the Snort-users mailing list