[Snort-users] stream5 reassembly and split-tcp handshaking
kungupanda at ...11827...
Mon Apr 25 13:55:59 EDT 2011
There has been a lot of press recently regarding exploits using tcp
split handshaking to evading IDS/IPS solutions:
(a) How does snort/stream5 handle split-tcp handshakes ?
(b) Does snort maintain correct flow directionality when
reassembling split-tcp sessions ?
(c) Are there signatures to detect attempts to establish split-tcp
More information about the Snort-users