2) Explain what does it mean when an IDS is located at the Host or the Network. What information can you obtain from eac
-
- Site Admin
- Posts: 899603
- Joined: Mon Aug 02, 2021 8:13 am
2) Explain what does it mean when an IDS is located at the Host or the Network. What information can you obtain from eac
www.cert.org/advisories/CA-2001 19.html; sid:1255; rev:7;) Url to assist: Snort Basics: How to Read and Write Snort Rules, Part 1 (hackers-arise.com) 4) Explain the capabilities of Tripwire and compare it to Snort.
2) Explain what does it mean when an IDS is located at the Host or the Network. What information can you obtain from each type of IDS? 3) Given the following Sort rule, describe what it does? flow:to_server,established; alert tcp $EXTERNAL_NET any -> 10.200.0.0/24 80 (msg: "WEB-IIS CodeRed v2 root.exe access"; uricontent:"/root.exe"; nocase; classtype:web application-attack; reference:url,