Question: Computer Science Cyber Security Questions. I will give thumb up! Consider the SNORT rule: alert tcp SHOME-NET any $EXTERNAL-NET 66667000 (msg CHAT IRC message, flow
Computer Science Cyber Security Questions. I will give thumb up!

Consider the SNORT rule: alert tcp SHOME-NET any $EXTERNAL-NET 66667000 (msg "CHAT IRC message", flow established, content."PRIVMSG": nocase, classtype policy-violation, sid: 1463, rev 6,) Explain what the snort rule does by answering 1) What type of connections would the rule apply to? 2) What type of traffic is being monitored? 3) Is there any additional requirement on the traffic
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
