Question: (1) Write a snort rule to detect a brute force SSH login attempt similar to what you performed in Lab 2. Explain the rule options
(1)
Write a snort rule to detect a brute force SSH login attempt similar to what you performed in Lab 2. Explain the rule options you chose and describe why they trigger an alert for the specified behavior. Describe a scenario which might result in your rule producing a false positive alert.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
