Detection of packets with no TCP flags set

eshelton <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CADOaRAnE=DDr3jgc90ns2KjJ2yV5CqEVvb_MKV1CYaRvEL_MRQ@mail.gmail.com>
Good evening,

My Google-fu is failing me right now, so I wanted to reach out to the list
to see if anyone has ever attempted to use Zeek to detect packets with no
TCP flags set?

In Snort land, a signature would look something like this:

alert tcp $HOME_NET any -> $EXTERNAL_NET 443 (msg:"LOCAL Port 443 and no
TCP flags set"; flags:0; classtype:misc-activity; sid:7;)

Before anyone asks, I'll just ahead and state that "yes Virginia, these
packets do really exist in the real world..." (though rare).

Thanks in advance,

-E

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.