Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: Stream5 Global Configuration Up: Stream5 Previous: Stream API   Contents

Anomaly Detection

TCP protocol anomalies, such as data on SYN packets, data received outside the TCP window, etc are configured via the detect_anomalies option to the TCP configuration. Some of these anomalies are detected on a per-target basis. For example, a few operating systems allow data in TCP SYN packets, while others do not.



Steven Sturges 2008-04-01