Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: sfPortscan Alert Output Up: sfPortscan Previous: sfPortscan Configuration   Contents

Format

preprocessor sfportscan: proto <protocols> \
scan_type <portscan|portsweep|decoy_portscan|distributed_portscan|all>\
sense_level <low|medium|high> watch_ip <IP or IP/CIDR> ignore_scanners <IP list>\
ignore_scanned <IP list> logfile <path and filename>

Figure 2.6: sfPortscan Preprocessor Configuration
\begin{figure}\begin{verbatim}preprocessor flow: stats_interval 0 hash 2
pre...
...o { all } \
scan_type { all } \
sense_level { low }\end{verbatim}
\end{figure}



Steven Sturges 2007-05-11