Detection of packets with no TCP flags set
eshelton <[email protected]>
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CADOaRAnE=DDr3jgc90ns2KjJ2yV5CqEVvb_MKV1CYaRvEL_MRQ@mail.gmail.com> |
Good evening, My Google-fu is failing me right now, so I wanted to reach out to the list to see if anyone has ever attempted to use Zeek to detect packets with no TCP flags set? In Snort land, a signature would look something like this: alert tcp $HOME_NET any -> $EXTERNAL_NET 443 (msg:"LOCAL Port 443 and no TCP flags set"; flags:0; classtype:misc-activity; sid:7;) Before anyone asks, I'll just ahead and state that "yes Virginia, these packets do really exist in the real world..." (though rare). Thanks in advance, -E _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek