Snort 规则匹配域名 maths.gzhu.edu.cn 产生 HTTP 访问报警
使用 Snort 规则匹配域名 'maths.gzhu.edu.cn' 并产生 HTTP 访问报警
Snort 规则可以利用 content 字段匹配特定的域名,例如 'maths.gzhu.edu.cn',从而产生 HTTP 协议访问该域名的报警。以下是一个示例规则:
alert tcp any any -> any 80 (msg:'HTTP access to maths.gzhu.edu.cn'; content:'Host: maths.gzhu.edu.cn'; http_header; sid:1000001; rev:1;)
该规则的解释如下:
alert tcp any any -> any 80:表示监测所有 TCP 流量,源 IP 和源端口和目的 IP 和目的端口不限制,目的端口为 80(HTTP 端口)。msg:'HTTP access to maths.gzhu.edu.cn':表示报警信息为“HTTP 访问 'maths.gzhu.edu.cn'”。content:'Host: maths.gzhu.edu.cn'; http_header;:表示匹配 HTTP 报文头中Host字段为 'maths.gzhu.edu.cn' 的请求。sid:1000001:表示规则唯一标识符为 1000001。rev:1:表示规则版本为 1。
通过以上规则,Snort 可以监测网络流量,一旦发现 HTTP 请求中 Host 字段值为 'maths.gzhu.edu.cn',就会触发报警。
原文地址: https://www.cveoy.top/t/topic/nXLz 著作权归作者所有。请勿转载和采集!