3459.txt
来自「snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具」· 文本 代码 · 共 62 行
TXT
62 行
Rule:--Sid:3459--Summary:This event is generated when activity by Peer-to-Peer (p2p) clients is detected.--Impact:Informational event. Unauthorized use of a p2p client may be in progress.--Detailed Information:This event indicates that use of a p2p client has been detected. This may be against corporate policy. p2p clients connect to other p2p clients to share files, commonly music and video files but can be configured to share any file on the local machine.This activity may not only use bandwidth but may also be used to transfer company confidential information to unauthorized hosts externalto the protected network bypassing other security measures in place.This rule detects activity from Manolito p2p client applications.--Affected Systems: Any host using a Manolito p2p client.--Attack Scenarios:This is indicative of the use of a p2p client.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:Check the host and uninstall any p2p client found.--Contributors:Sourcefire Research TeamAlex Kirk <akirk@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?