Project

General

Profile

Actions

Feature #8250

open

rules: distinct ip counting logic

Added by Ofer Dagan 12 days ago. Updated 3 days ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Effort:
low
Difficulty:
Label:

Description

In continuous to this ticket - https://redmine.openinfosecfoundation.org/issues/7928.

Implementing now unique_on options for src_ip and dst_ip.

Example for host scan rule:
alert tcp any any -> any any (msg:"Potential TCP SYN Scan Detected"; flags:S; threshold:type both, track by_src, count 50, seconds 60, unique_on dst_ip; classtype:network-scan; sid:1000001; rev:1;)

Actions #2

Updated by Philippe Antoine 3 days ago

  • Assignee set to Ofer Dagan
Actions #3

Updated by Philippe Antoine 3 days ago

  • Status changed from In Progress to In Review
Actions

Also available in: Atom PDF