|
|
|
|
Snort Forums Archive
Archive Home » Snort Newbies » Snort / Firewall Integration Question
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
Snort / Firewall Integration Question
Posted by mmccarn on March 22, 2005 03:23:35
Is there a way to use SNORT to block traffic from attacking hosts for a period that increases based on the number of attacks experienced from that host?
For example, block traffic from the attacking host for 5 minutes after the first attack, 25 minutes after the 2nd attack, 125 minutes after the 3rd attack (or 5 minutes, 10 minutes, 20 minutes...)
Also, if I'm attacked from 2 hosts on the same subnet, can I block traffic from the entire subnet along the same lines as outlined above?
Lastly, can I block only the protocol used in the attack? That is, if I'm attacked on POP3 (dictionary attack) - can I block POP3 but leave SMTP open?
Thanks!
|
|
Posted by roesch on March 23, 2005 06:24:14
Check out http://www.snortsam.net/, it may do what you're looking for.
-Marty
|
|
|
|
|
|