- ÂÛ̳»ÕÕÂ:
- 0
|
Tag\r\n\r\nÕâ¸ö¹Ø¼ü×ÖÔÊÐí¹æÔò¼Ç¼²»½ö½öÊÇ´¥·¢ÕâÌõ¹æÔòµÄÄǸöÊý¾Ý°ü¡£Ò»µ©Ò»Ìõ¹æÔò±»´¥·¢£¬À´×ÔÕâ¸öÖ÷»úµÄÊý¾Ý°ü½«±»ÌùÉÏ¡°±êÇ©¡±¡£±»ÌùÉϱêÇ©µÄÊý¾ÝÁ÷½«±»¼Ç¼ÓÃÓÚËæºóµÄÏìÓ¦´úÂëºÍÌá½»¹¥»÷Á÷Á¿µÄ·ÖÎö¡£\r\n\r\n¸ñʽ£º\r\ntag: , , , [direction]\r\n\r\ntype\r\n\r\nsession ¼Ç¼´¥·¢ÕâÌõ¹æÔòµÄ»á»°µÄÊý¾Ý°ü\r\nhost ¼Ç¼¼¤»îtag¹æÔòµÄÖ÷»úµÄËùÓÐÊý¾Ý°ü£¨ÕâÀォʹÓÃ[direction]ÐÞÊδÊ\r\ncount Count Ö¸¶¨Ò»¸öµ¥Î»µÄÊýÁ¿¡£Õâ¸öµ¥Î»Óɸø³ö¡£\r\nmetric\r\npackets ±ê¼ÇÖ÷»ú£¯»á»°µÄ¸öÊý¾Ý°ü¡£\r\nseconds ±ê¼ÇÖ÷»ú£¯»á»°µÄÃë¡£\r\n\r\nÀý×Ó£º\r\nalert tcp !$HOME_NET any -> $HOME_NET 143 (flags: A+; content: \"|e8 c0ff ffff|/bin/sh\"; tag: host, 300, packets, src; msg: \"IMAP Buffer overflow, tagging!\"\r\nalert tcp !$HOME_NET any -> $HOME_NET 23 (flags: S; tag: session, 10, seconds; msg: \"incoming telnet session\"\r\n\r\nIp_proto\r\nIp_proto¹Ø¼ü×ÖÔÊÐí¼ì²âIPÐÒéÍ·¡£ÕâЩÐÒé¿ÉÒÔÊÇÓÉÃû×Ö±êʶµÄ£¬²Î¿¼/etc/protocolsÎļþ¡£ÔÚ¹æÔòÖÐÒª½÷É÷ʹÓÃip_protocol¹Ø¼ü×Ö¡£\r\n\r\n¸ñʽ£º\r\nip_proto:[!] ;\r\n\r\nÀý×Ó£º br> alert ip !$HOME_NET any -> $HOME_NET any (msg: \"IGMP traffic detected\"; ip_proto: igmp\r\n\r\nSameIP\r\n\r\nSameip¹Ø¼ü×ÖÔÊÐí¹æÔò¼ì²âÔ´IPºÍÄ¿µÄIPÊÇ·ñÏàµÈ¡£\r\n\r\n¸ñʽ£º\r\nsameip;\r\n\r\nÀý×Ó£º\r\nalert ip $HOME_NET any -> $HOME_NET any (msg: \"SRC IP == DST IP\"; sameip\r\n\r\nRegex\r\nÕâ¸öÄ£¿éÏÖÔÚ»¹ÕýÔÚ¿ª·¢£¬ËùÒÔÔÚµ±Ç°µÄ²úÆ·¹æÔò¼¯Öл¹²»ÄÜʹÓá£Èç¹ûʹÓõĻ°£¬Ëü½«´¥·¢Ò»¸ö´íÎóÐÅÏ¢¡£\r\n\r\nFlow\r\n\r\nÕâ¸öÑ¡ÏîÒªºÍTCPÁ÷Öؽ¨ÁªºÏʹÓá£ËüÔÊÐí¹æÔòÖ»Ó¦Óõ½Á÷Á¿Á÷µÄij¸ö·½ÏòÉÏ¡£Õ⽫ÔÊÐí¹æÔòÖ»Ó¦Óõ½¿Í»§¶Ë»òÕß·þÎñÆ÷¶Ë¡£Õ⽫ÄÜ°ÑÄÚÍø¿Í»§¶ËÁ÷ÀÀwebÒ³ÃæµÄÊý¾Ý°üºÍÄÚÍø·þÎñÆ÷Ëù·¢Ë͵ÄÊý¾Ý°üÇø·Ö¿ªÀ´¡£Õâ¸öÈ·¶¨µÄ¹Ø¼ü×ÖÄܹ»´úÌæ±êÖ¾£ºA+ Õâ¸ö±êÖ¾ÔÚÏÔʾÒѽ¨Á¢µÄTCPÁ¬½Óʱ¶¼½«±»Ê¹Óá£\r\n\r\nÑ¡Ï\r\nto_client ´¥·¢·þÎñÆ÷ÉÏ´ÓAµ½BµÄÏìÓ¦¡£\r\nto_server ´¥·¢¿Í»§¶ËÉÏ´ÓAµ½BµÄÇëÇó¡£\r\nfrom_client ´¥·¢¿Í»§¶ËÉÏ´ÓAµ½BµÄÇëÇó¡£\r\nfrom_server´¥·¢·þÎñÆ÷ÉÏ´ÓAµ½BµÄÏìÓ¦¡£\r\nestablished Ö»´¥·¢ÒѾ½¨Á¢µÄTCPÁ¬½Ó¡£\r\nstateless ²»¹ÜÁ÷´¦ÀíÆ÷µÄ״̬¶¼´¥·¢£¨Õâ¶Ô´¦ÀíÄÇЩÄÜÒýÆð»úÆ÷±ÀÀ£µÄÊý¾Ý°üºÜÓÐÓá£\r\nno_stream ²»ÔÚÖؽ¨µÄÁ÷Êý¾Ý°üÉÏ´¥·¢£¨¶Ôdsize ºÍ stream4 ÓÐÓá£\r\nonly_stream Ö»ÔÚÖؽ¨µÄÁ÷Êý¾Ý°üÉÏ´¥·¢¡£\r\n\r\n¸ñʽ£º\r\nflow:[to_client|to_server|from_client|from_server|established|stateless|no_stream|only_stream]}\r\n\r\nÀý×Ó£º\r\nalert tcp !$HOME_NET any -> $HOME_NET 21 (flow: from_client; content: \"CWD incoming\"; nocase; msg: \"cd incoming detected\"; )\r\nalert tcp !$HOME_NET 0 -> $HOME_NET 0 (msg: \"ort 0 TCP traffic\"; flow: stateless\r\n\r\nFragoffset\r\n\r\nÕâ¸ö¹Ø¼ü×ÖÔÊÐí°ÑIP·Ö¶ÎÆ«ÒÆÖµºÍÒ»¸öÊ®½øÖÆÊýÏà±È½Ï¡£ÎªÁË×¥µ½Ò»¸öIP»á»°µÄµÚÒ»¸ö·Ö¶Î£¬Äã¿ÉÒÔʹÓÃÕâ¸öfragbits¹Ø¼ü×Ö²¢ÇÒºÍfragoffset£º0 Ñ¡ÏîÒ»Æð²é¿´¸ü¶àµÄ·Ö¶ÎÑ¡Ïî¡£\r\n\r\n¸ñʽ£º\r\nfragoffset:[<|>]\r\n\r\nÀý×Ó£º\r\nalert ip any any -> any any (msg: \"First Fragment\"; fragbits: M; fragoffset: 0\r\n\r\nRawbytes\r\n\r\nRawbytes¹Ø¼ü×ÖÔÊÐí¹æÔò²é¿´telnet ½âÂëÊý¾ÝÀ´´¦Àí²»³£¼ûµÄÊý¾Ý¡£Õ⽫ʹµÃtelnet ÐÒé´úÂë¶ÀÁ¢ÓÚÔ¤´¦Àí³ÌÐòÀ´¼ì²â¡£ÕâÊǶÔÇ°ÃæµÄcontent µÄÒ»¸öÐÞÊΡ£\r\n\r\n¸ñʽ£º\r\nrawbytes;\r\n\r\nÀý×Ó£º\r\nalert tcp any any -> any any (msg: \"Telnet NOP\"; content: \"|FF F1|\"; rawbytes\r\n\r\ndistance\r\n\r\ndistance¹Ø¼ü×ÖÊÇcontent¹Ø¼ü×ÖµÄÒ»¸öÐÞÊδʣ¬È·ÐÅÔÚʹÓÃcontentʱģʽƥÅä¼äÖÁÉÙÓÐN¸ö×Ö½Ú´æÔÚ¡£Ëü±»Éè¼Æ³ÉÔÚ¹æÔòÑ¡ÏîÖкÍÆäËûÑ¡ÏîÁªºÏʹÓá£\r\n\r\n¸ñʽ£º\r\ndistance: ;\r\n\r\nÀý×Ó£º\r\nalert tcp any any -> any any (content: \"2 Patterns\"; content: \"ABCDE\"; content: \"EFGH\"; distance: 1\r\n\r\nWithin\r\n\r\nWinthin¹Ø¼ü×ÖÊÇcontent¹Ø¼ü×ÖµÄÒ»¸öÐÞÊδʣ¬È·±£ÔÚʹÓÃcontentʱģʽƥÅä¼äÖÁ¶àÓÐN¸ö×Ö½Ú´æÔÚ¡£Ëü±»Éè¼Æ³ÉÔÚ¹æÔòÑ¡ÏîÖкÍdistanceÑ¡ÏîÁªºÏʹÓá£\r\n\r\n¸ñʽ£º\r\nwithin: ;\r\n\r\nÀý×Ó£º\r\nalert tcp any any -> any any (content: \"2 Patterns\"; content: \"ABCDE\"; content: \"EFGH\"; within: 10\r\n\r\nByte_Test\r\n\r\n²âÊÔÒ»¸ö×Ö½ÚµÄÓòΪÌض¨µÄÖµ¡£Äܹ»²âÊÔ¶þ½øÖÆÖµ»òÕß°Ñ×Ö½Ú×Ö·û´®×ª»»³É¶þ½øÖƺóÔÙ²âÊÔ¡£\r\n\r\n¸ñʽ£ºbyte_test: , , , [[relative],[big],[little],[string],[hex],[dec],[oct]]\r\nbytes_to_convert ´ÓÊý¾Ý°üÈ¡µÃµÄ×Ö½ÚÊý¡£\r\noperator ¶Ô¼ì²âÖ´ÐеIJÙ×÷ (<,>,=,!)¡£\r\nvalue ºÍת»»ºóµÄÖµÏà²âÊÔµÄÖµ¡£\r\noffset ¿ªÊ¼´¦ÀíµÄ×Ö½ÚÔÚ¸ºÔØÖеÄÆ«ÒÆÁ¿¡£\r\nrelative ʹÓÃÒ»¸öÏà¶ÔÓÚÉÏ´ÎģʽƥÅäµÄÏà¶ÔµÄÆ«ÒÆÁ¿¡£\r\nbig ÒÔÍøÂç×Ö½Ú˳Ðò´¦ÀíÊý¾Ý£¨È±Ê¡£©¡£\r\nlittle ÒÔÖ÷»ú×Ö½Ú˳Ðò´¦ÀíÊý¾Ý¡£\r\nstring Êý¾Ý°üÖеÄÊý¾ÝÒÔ×Ö·û´®ÐÎʽ´æ´¢¡£\r\nhex °Ñ×Ö·û´®Êý¾Ýת»»³ÉÊ®Áù½øÖÆÊýÐÎʽ¡£\r\ndec °Ñ×Ö·û´®Êý¾Ýת»»³ÉÊ®½øÖÆÊýÐÎʽ¡£\r\noct °Ñ×Ö·û´®Êý¾Ýת»»³É°Ë½øÖÆÊýÐÎʽ¡£\r\n\r\nÀý×Ó£º\r\nalert udp $EXTERNAL_NET any -> $HOME_NET any (msg:\"AMD procedure 7 plog overflow \"; content: \"|00 04 93 F3|\"; content: \"|00 00 00 07|\"; distance: 4; within: 4; byte_test: 4,>, 1000, 20, relative\r\n\r\nalert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:\"AMD procedure 7 plog overflow \"; content: \"|00 04 93 F3|\"; content: \"|00 00 00 07|\"; distance: 4; within: 4; byte_test: 4, >,1000, 20, relative;)\r\n\r\nByte_Jump\r\n\r\nByte_jump Ñ¡ÏîÓÃÀ´È¡µÃÒ»¶¨ÊýÁ¿µÄ×Ö½Ú£¬²¢°ÑËüÃÇת»»³ÉÊý×ÖÐÎʽ£¬Ìø¹ýһЩ×Ö½ÚÒÔ½øÒ»²½½øÐÐģʽƥÅä¡£Õâ¾ÍÔÊÐíÏà¶ÔģʽƥÅäÔÚÍøÂçÊý¾ÝÖнøÐÐÊý×ÖֵƥÅä¡£\r\n\r\n¸ñʽ£º\r\nbyte_jump: , [[relative],[big],[little],[string],[hex],[dec],[oct],[align]]\r\n\r\nbytes_to_convert ´ÓÊý¾Ý°üÖÐÑ¡³öµÄ×Ö½ÚÊý¡£\r\noffset ¿ªÊ¼´¦ÀíµÄ×Ö½ÚÔÚ¸ºÔØÖеÄÆ«ÒÆÁ¿¡£\r\nrelative ʹÓÃÒ»¸öÏà¶ÔÓÚÉÏ´ÎģʽƥÅäµÄÏà¶ÔµÄÆ«ÒÆÁ¿¡£\r\nbig ÒÔÍøÂç×Ö½Ú˳Ðò´¦ÀíÊý¾Ý£¨È±Ê¡£©¡£\r\nlittle ÒÔÖ÷»ú×Ö½Ú˳Ðò´¦ÀíÊý¾Ý¡£\r\nstring Êý¾Ý°üÖеÄÊý¾ÝÒÔ×Ö·û´®ÐÎʽ´æ´¢¡£\r\nhex °Ñ×Ö·û´®Êý¾Ýת»»³ÉÊ®Áù½øÖÆÊýÐÎʽ¡£\r\ndec °Ñ×Ö·û´®Êý¾Ýת»»³ÉÊ®½øÖÆÊýÐÎʽ¡£\r\noct °Ñ×Ö·û´®Êý¾Ýת»»³É°Ë½øÖÆÊýÐÎʽ¡£\r\nalign ÒÔ32λΪ±ß½ç¶Ôת»»µÄ×Ö½ÚÊý¶ÔÆ룬¼´×ª»»µÄ×Ö½ÚÊýΪ4µÄ±¶Êý¡£\r\n\r\nÀý×Ó£º\r\nalert udp any any -> any 32770:34000 (content: \"|00 01 86 B8|\"; content: \"|00 00 00 01|\"; distance: 4; within: 4; byte_jump: 4, 12, relative, align; byte_test: 4, >, 900, 20, relative; msg: \"statd format string buffer overflow\";) |
|