Question: kalickali: $ mousepad / etc / snort / snort . conf File Edit Search View Document Help alert tcp $HOME _ NET any diamond $EXTERNAL
kalickali: $ mousepad etcsnortsnortconf
File Edit Search View Document Help
alert tcp $HOMENET any diamond $EXTERNALNET :msg: "CHAT IRC message"; flow:established;
content:"PRIVMSG ; nocase; classtype:policyviolation; sid:; rev:;
a What type of connection this rule is applied toinclude protocol name
b What traffic is monitored? include source, destination, ports, and directions
c Any additional requirementcharacteristics in the traffic that the rule looks for?
d What happens when the rule is matched? include action
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
