proto { all } memcap { 10000000 } sense_level { low } # syslog # output alert_syslog: LOG_AUTH LOG_ALERT output alert_syslog: LOG_LOCAL0 Snortの場合(2/3)
24 ・/etc/snort/snort.conf
portscanのプリプロセッサを有効
/var/log/syslogへ出力
・/etc/rsyslog.conf
local0.* /var/log/snort/snort.log ・/etc/snort/rules/scan.rules
#alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"SCAN nmap XMAS"; flow:stateless; flags:FPU,12; reference:arachnids,30; classtype:attempted-recon; sid:1228; rev:7;) alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"SCAN nmap XMAS FlexResp"; flow:stateless; flags:FPU,12; reference:arachnids,30; classtype:attempted-recon; sid:1228; rev:7; resp:rst_all) FlexRespでRSTパケットを送るという指定
▪参考情報
・FlexResp で自己防衛を行う (2019-05-18)
http://safe-linux.homeip.net/security/linux-snort3-12.html