| Snort :: Rule. Snort :: RuleÀº Snort ±ÔÄ¢À» µ¿ÀûÀ¸·Î ±¸ÃàÇϱâÀ§ÇÑ Perl È®ÀåÀÚÀÔ´Ï´Ù. |
Áö±Ý ´Ù¿î·Îµå |
Snort :: Rule. ¼øÀ§ ¹× ¿ä¾à
- ƯÇã:
- Perl Artistic License
- °Ô½ÃÀÚ À¥»çÀÌÆ®:
- http://search.cpan.org/~saxjazman/Snort-Rule-1.03/lib/Snort/Rule.pm
Snort :: Rule. ű×
Snort :: Rule. ¼³¸í
Snort :: RuleÀº Snort ±ÔÄ¢À» µ¿ÀûÀ¸·Î ±¸ÃàÇϱâÀ§ÇÑ Perl È®ÀåÀÚÀÔ´Ï´Ù. Snort :: RuleÀº Snort ±ÔÄ¢À» µ¿ÀûÀ¸·Î ±¸ÃàÇϱâÀ§ÇÑ Perl È®ÀåÀÚÀÔ´Ï´Ù .Synopsis Snort :: RuleÀ» »ç¿ëÇϽʽÿÀ. $ rule = snort :: ±ÔÄ¢ -> new (-cate => '°æ°í', -proto => 'tcp', -src => 'any', -sport => 'any', -dir => '-> ', -dst =>'192.188.1.1 ', -dport =>'44444 ';); $ ±ÔÄ¢ -> opts ( 'msg', 'test ±ÔÄ¢ "); $ rule-> opts ('ÀÓ°è °ª ','À¯Çü Á¦ÇÑ, track by_src, Ä«¿îÆ® 1, ÃÊ 3600 '); $ ±ÔÄ¢ -> opts ('sid ','500000 '); $ ·ê -> string ()À» ÀμâÇϽʽÿÀ. "n"; ¶Ç´Â $ rule ='°æ°í TCP $ smtp_servers any -> $ external_net 25 (msg : "ÃâÇ÷ - °¡ÀåÀÚ¸® Á¤Ã¥ SMTP US Top Secret Propin"; È帧 : To_Server, ¼³¸³; ÇÔÀ¯·® : "Á¦¸ñ | 3A |"pcre : "/ (topsecret | ts) // * propin * (? = // (25)? x ) / ISM "; CLASSTYPE : Á¤Ã¥ À§¹Ý; SID : 2002448; REV : 1;) '; $ ruch = snort :: ±ÔÄ¢ -> »õ (-parse => $ rule); $ ±ÔÄ¢ Àμâ -> string (). "n"; ÀÌ°ÍÀº ¸Å¿ì °£´ÜÇÑ snort ±ÔÄ¢ °³Ã¼ÀÔ´Ï´Ù. ±×°ÍÀº ½ºÅ©¸³Æ® µÈ µ¿Àû ±ÔÄ¢ »ý¼ºÀ» Çã¿ëÇϱâ À§ÇØ °³¹ßµÇ¾ú½À´Ï´Ù. ÀÌ»óÀûÀ¸·Î´Â µ¿ÀûÀ¸·Î ³ª»Û È£½ºÆ® ¸ñ·ÏÀ» °¡Á®°¥ ¼ö ÀÖÀ¸¸ç ±×·ÎºÎÅÍ Snort ±ÔÄ¢ °³Ã¼ ¹è¿À» ºôµå ÇÒ ¼ö ÀÖ½À´Ï´Ù. list. ±×·± ´ÙÀ½ String () ¸Þ¼µå¸¦ Snort ±ÔÄ¢ ÆÄÀÏ·Î »ç¿ëÇÏ¿© ÇØ´ç ¸ñ·ÏÀ» ¾¹´Ï´Ù. ¿ä±¸ »çÇ× : ¡¤ Perl.
Snort :: Rule. °ü·Ã ¼ÒÇÁÆ®¿þ¾î