这在Snort中是一个常见的问题,但是我不确定规则为什么触发。
以下规则来自Debian存储库。 显然它被devise为在5060端口上有超过300次命中时触发,并且如果它继续的话每60秒只会提醒一次。
/etc/snort/rules/community-sip.rules(添加空白,删除其他规则):
... alert ip any any -> any 5060 ( msg:"COMMUNITY SIP TCP/IP message flooding directed to SIP proxy"; threshold: type both, track by_src, count 300, seconds 60; classtype:attempted-dos; sid:100000160; rev:2; ) ...
http://manual.snort.org/node35.html
但规则似乎触发了什么与5060端口无关的东西。 例如,这是一个提醒:
例如,
[**] [1:100000160:2] COMMUNITY SIP TCP/IP message flooding directed to SIP proxy [**] [Classification: Attempted Denial of Service] [Priority: 2] 08/06-12:19:07.399163 1.2.3.4:61253 -> 5.6.7.8:22 TCP TTL:55 TOS:0x10 ID:59727 IpLen:20 DgmLen:52 DF ***A**** Seq: 0xE2B759E9 Ack: 0xB01D0B90 Win: 0xFFFF TcpLen: 32 TCP Options (3) => NOP NOP TS: 129954676 287277196
一些Googlesearch显示人们说“这是一个不好的规则”,但我看不出来。
我想我得到了这个。 在snort.org的文档中没有关于“alert ip”和端口号的信息。
以下说这是编写snort规则时常见的错误:
http://leonward.wordpress.com/2009/06/07/dumbpig-automated-checking-for-snort-rulesets/
我通过复制规则来修复它,指定TCP和UDP并更改规则SID。 我在community-sip.rules文件中重复了这个多重规则。
例如,
alert tcp any any -> any 5060 (msg:"COMMUNITY SIP TCP/IP message flooding directed to SIP proxy"; threshold: type both, track by_src, count 300, seconds 60; classtype:attempted-dos; sid:900000160; rev:2;) alert udp any any -> any 5060 (msg:"COMMUNITY SIP TCP/IP message flooding directed to SIP proxy"; threshold: type both, track by_src, count 300, seconds 60; classtype:attempted-dos; sid:910000160; rev:2;)
警报现在很安静。 一些testing规则(计数较低)在我testing时正确触发。