Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Newbies » rule logic for packets over time

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

rule logic for packets over time


Posted by redsox52 on March 17, 2005 11:59:39

Can Snort detect denial of service attacks, where you would need a rule like 'same source IP and same URL params more than 5 times in 5 seconds', or must all rules apply to a single packet?

Posted by roesch on March 19, 2005 17:19:25

Check out the README.thresholding file in the doc subdirectory of the Snort tarball.

-Marty