Snort mailing list archives

Re: Applying a rule on entire session


From: "Alex Butcher, ISC/ISYS" <Alex.Butcher () bristol ac uk>
Date: Wed, 08 Sep 2004 12:34:07 +0100



--On 08 September 2004 01:53 -0700 Dennis George <easyeinfo () yahoo com> wrote:


Hi,

flowbits and looking for the FIN and/or RST flags?

I mean to say that the rules should be applied to the reassembled data
chunk of the entire session. The rule should not be applied to each
packet coming.... instead after all the packet form a session then only
apply that rule.........

<http://www.snort.org/docs/snort_manual/node10.html#SECTION00314200000000000000>

Regards
Dennis

Best Regards,
Alex.
--
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing             GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9




-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: