Snort mailing list archives

about threshold


From: 강명훈 <mhkang589 () gmail com>
Date: Tue, 14 Jul 2015 23:38:54 +0900

Hi everyone.
I have made rules below.

alert udp any any -> 16x.12x.10x.2 53 (msg:"scan test"; threshold:type
threshold, track by_src, count 1, seconds 2; classtype:TEST; sid:1999949;)
alert udp any any -> 16x.12x.10x.2 53 (msg:"flood test"; threshold:type
threshold, track by_dst, count 1, seconds 2; classtype:TEST; sid:1999950;)


And i have tested by nslookup.
It happened two packets(A, AAAA record) per one dns query.

My expectation that happen two 'scan test' events.
But it happened two 'scan test' events and two 'flood test' events.

Why different rules matching the same packet?
Is it normal?

-- 

*kangmyounghun.blogspot.kr <http://kangmyounghun.blogspot.kr/>*
*kr.linkedin.com/pub/myounghun-kang/74/238/93a*
<http://kr.linkedin.com/pub/myounghun-kang/74/238/93a>
------------------------------------------------------------------------------
Don't Limit Your Business. Reach for the Cloud.
GigeNET's Cloud Solutions provide you with the tools and support that
you need to offload your IT needs and focus on growing your business.
Configured For All Businesses. Start Your Cloud Today.
https://www.gigenetcloud.com/
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

Current thread: