Question: Select the correct statement ( s ) for the following snort rule. alert tcp $EXTERNAL _ NET any - > $HOME _ NET 1 2
Select the correct statements for the following snort rule.
alert tcp $EXTERNALNET any $HOMENET msg:"MALWAREOTHER mstream client to handler"; flow:toserver,established; content:"; metadata:ruleset community; reference:cve,; classtype:attempteddos; sid:; rev:;
This rule concerns whether the TCP payload contains the following byte sequence
This rule does not concern which IP in a TCP session initiates this session ie serving as the client
If an external host directly sends a TCP packet, with the destination port of to a host in the homeinternal network, without firstly establishing a TCP connection, this packet will never trigger the alert of this rule.
If a TCP packet with the source port of is sent from the external network to the internal network, this packet will never trigger the alert of this rule.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
