Snort 规则:检测访问 maths.gzhu.edu.cn 的 HTTP 请求
使用 Snort 规则的 content 字段,可以匹配域名 'maths.gzhu.edu.cn',从而产生访问该域名的 HTTP 协议报警。以下是一条示例规则:
alert tcp any any -> any any (msg:'HTTP access to maths.gzhu.edu.cn'; content:'Host\x3a\x20maths.gzhu.edu.cn'; http_header; sid:100001; rev:1;)
解释:
- alert:表示发现匹配规则后要发出警报
- tcp:表示匹配 TCP 协议
- any any -> any any:表示匹配任意源 IP 和源端口,任意目的 IP 和目的端口的流量
- msg:'HTTP access to maths.gzhu.edu.cn':表示警报消息内容
- content:'Host\x3a\x20maths.gzhu.edu.cn';:表示匹配 HTTP 头部中 Host 字段值为 'maths.gzhu.edu.cn' 的流量
- http_header:表示匹配 HTTP 协议头部
- sid:100001:表示规则的唯一标识符
- rev:1:表示规则的版本号
通过这条规则,Snort 可以检测到所有尝试访问 'maths.gzhu.edu.cn' 域名的 HTTP 请求,并发出相应的警报。
原文地址: https://www.cveoy.top/t/topic/nXLw 著作权归作者所有。请勿转载和采集!