Question: What does this Snort rule do? alert tcp $EXTERNAL_NET any - > $HOME_NET any (msg: SCAN SYN FIN; flags: SF, 12; reference: arachnids,

What does this Snort rule do? alert tcp \$EXTERNAL_NET any - > \$HOME_NET any \ (msg: "SCAN SYN FIN"; flags: SF, 12; \ reference: arachnids, 198; classtype: attempted-recon;) Select one: a. Generates an alert if a packet arrives with the SYN and FIN bits set, which would be an invalid packet b. Logs alerts if packets arrive from the 12.0.0.0/8 network destined to the 192.168.0.0/16 network c. Scans packets for the SYN bit and sends a FIN if any arrive from the EXTERNAL_NET d. Scans packets for the SF flags and sends a FIN if any are destined to the \$HOME_NET
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
