⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 477.txt

📁 snort入侵检测规则文件2.4 Snort是众所周知的网络入侵检测工具
💻 TXT
字号:
Rule:--Sid:477--Summary:This event is generated when a network host generates an ICMP source quenchdatagram.--Impact:ICMP source quench message are generated by gateway devices that no longerhave the buffer space needed to queue datagrams for output to the next route.This could be an indication of a routing problem, network capacity problem, or on going Denial of Service attack.--Detailed Information:ICMP source quench messasges are generated when a gateway device runs outof buffer space to process incoming network traffic.  This is an informationalmessage that is generated in an attempt to inform the remote host generatingthe traffic to limit the speed at which it is sending network traffic tothe remote host.--Attack Scenarios:Denial of Service.  Attackers could potenially use ICMP source quench datagramsto rate limit a remote host that listens to unsolicited ICMP source quench datagrams.   --Ease of Attack:Numerous tools and scripts can generate this type of datagram.--False Positives:Legitimate source quench datagrams will trigger this rule.--False Negatives:None known--Corrective Action:Use ingress filtering to block incoming ICMP source quench datagrams.--Contributors:Original rule writer unknownSourcefire Research TeamMatthew Watchinski (matt.watchinski@sourcefire.com)--Additional References:http://www.whitehats.com/info/IDS238--

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -