Given the following Snort rule alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"SCAN SYN FIN";flags:SF; reference: arachnids,198; classtype:attempted- recon; sid:624; rev:1;) Question: If we were to re-define the above rule for packets coming from the EXTERNAL_NET using ports 20 through 25 (ftp through smtp), other than using the option key word or field 'any', how can we rewrite this rule? Note: the rule must syntactically be correct so that Snort doesn't complain about incorrect rule.) Your Answer:

Computer Networking: A Top-Down Approach (7th Edition)
7th Edition
ISBN:9780133594140
Author:James Kurose, Keith Ross
Publisher:James Kurose, Keith Ross
Chapter1: Computer Networks And The Internet
Section: Chapter Questions
Problem R1RQ: What is the difference between a host and an end system? List several different types of end...
icon
Related questions
Question
Given the following Snort rule
alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"SCAN
SYN FIN";flags:SF; reference: arachnids,198; classtype:attempted-
recon; sid:624; rev:1;)
Question: If we were to re-define the above rule for packets
coming from the EXTERNAL_NET using ports 20 through 25 (ftp
through smtp), other than using the option key word or field 'any,
how can we rewrite this rule?
(Note: the rule must syntactically be correct so that Snort doesn't
complain about incorrect rule.)
Your Answer:
Transcribed Image Text:Given the following Snort rule alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"SCAN SYN FIN";flags:SF; reference: arachnids,198; classtype:attempted- recon; sid:624; rev:1;) Question: If we were to re-define the above rule for packets coming from the EXTERNAL_NET using ports 20 through 25 (ftp through smtp), other than using the option key word or field 'any, how can we rewrite this rule? (Note: the rule must syntactically be correct so that Snort doesn't complain about incorrect rule.) Your Answer:
Expert Solution
trending now

Trending now

This is a popular solution!

steps

Step by step

Solved in 3 steps with 2 images

Blurred answer
Recommended textbooks for you
Computer Networking: A Top-Down Approach (7th Edi…
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
Computer Organization and Design MIPS Edition, Fi…
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
Network+ Guide to Networks (MindTap Course List)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
Concepts of Database Management
Concepts of Database Management
Computer Engineering
ISBN:
9781337093422
Author:
Joy L. Starks, Philip J. Pratt, Mary Z. Last
Publisher:
Cengage Learning
Prelude to Programming
Prelude to Programming
Computer Engineering
ISBN:
9780133750423
Author:
VENIT, Stewart
Publisher:
Pearson Education
Sc Business Data Communications and Networking, T…
Sc Business Data Communications and Networking, T…
Computer Engineering
ISBN:
9781119368830
Author:
FITZGERALD
Publisher:
WILEY