Question: (1) Write a snort rule to detect a brute force SSH login attempt similar to what you performed in Lab 2. Explain the rule options

(1)

Write a snort rule to detect a brute force SSH login attempt similar to what you performed in Lab 2. Explain the rule options you chose and describe why they trigger an alert for the specified behavior. Describe a scenario which might result in your rule producing a false positive alert.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!