[Snort-users] About rule setting

Ryota Kurokawa r-kurokw at ist.osaka-u.ac.jp
Wed Sep 27 00:20:11 EDT 2017


Hi

I recently started using snort.
I think that it is necessary to set rules when starting IDS mode and 
recording packets. I was successful to catch icmp packets.
For example, can we record packets with a speed higher than a certain 
speed, such as malicious traffic (such as ping bombs)?

Thanks.

-- 
Name: Kurokawa Ryota
mail: r-kurokw at ist.osaka-u.ac.jp




More information about the Snort-users mailing list