TAILIEUCHUNG - snort 2.1 intrusion detection second edition phần 5

Sau khi thực hiện xong việc cài đặt của phần mềm, bạn sẽ được trả lại vào lệnh nhanh chóng và với may mắn, miễn chọn SnortSnarf tính năng bao gồm một công cụ để tạo ra sự cố tính năng tương tự như nhóm ACID cảnh báo và gửi thư điện tử. Cài đặt của nó được mô tả trong trong gói phân phối SnortSnarf. | 274 Chapter 6 Preprocessors Simpo PDF Merge and Split Unregistered Version - http portscan2 does require the conversation preprocessor. In essence conversation provides a state engine that keeps state on TCP UDP and ICMP it compiles information on which hosts have contacted which and on which ports. conversation isn t really used for its own sake it simply provides a data compilation mechanism for portscan2. The flow and flow-portscan preprocessors have now superseded these two preprocessors. We still cover the portscan2 and conversation preprocessors solely because they haven t yet been removed from the codebase and may thus still be in use. Configuring the portscan2 Preprocessor To understand how portscan2 is configured you will need to understand how it operates. portscan2 keeps detailed short-term records of all session-initiating packets potential probes that cross Snort from any single host to any other single host. In certain situations portscan2 can be configured to ignore hosts and ports basically it watches to see if any one host sends too many probes and then issues alerts if it does. portscan2 accomplishes this by maintaining counts and waiting to see if thresholds are crossed. The criteria for crossed thresholds is based on either too many different destination ports or hosts. portscan2 maintains this information for a short period of time which means that it won t necessarily detect a slow and thus stealthy scan. portscan2 is activated by adding a preprocessor portscan2 line in Snort s configuration file . Optionally you can add a colon after portscan2 and add a comma-delimited set of parameters settings like so preprocessor portscan2 targets_max 1000 scanners_max 1000 port_limit 20 As we ll discuss some of this preprocessor s defaults are almost certainly too low. Let s examine the parameters that you can set targets_max Defaulting to 1000 this resource-control parameter controls how many targets that portscan2 will keep .

Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.