Question: What does this Snort rule do? alert tcp $EXTERNAL_NET any - > $HOME_NET any (msg: SCAN SYN FIN; flags: SF, 12; reference: arachnids,

 What does this Snort rule do? alert tcp \$EXTERNAL_NET any -

What does this Snort rule do? alert tcp \$EXTERNAL_NET any - > \$HOME_NET any \ (msg: "SCAN SYN FIN"; flags: SF, 12; \ reference: arachnids, 198; classtype: attempted-recon;) Select one: a. Generates an alert if a packet arrives with the SYN and FIN bits set, which would be an invalid packet b. Logs alerts if packets arrive from the 12.0.0.0/8 network destined to the 192.168.0.0/16 network c. Scans packets for the SYN bit and sends a FIN if any arrive from the EXTERNAL_NET d. Scans packets for the SF flags and sends a FIN if any are destined to the \$HOME_NET

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!