Mal Ware Dynamic Analysis 06
Mal Ware Dynamic Analysis 06
Part 6
Veronica Kovah
vkovah.ost at gmail
http://opensecuritytraining.info/MalwareDynamicAnalysis.html
• Rule headers
– Rule action tells Snort what to do (e.g. alert, log, drop)
– IP addresses in Classless Inter-Domain Routing (CIDR) notation
– Port numbers
– Direction operator should be “->” or “<>” (bidirectional)