rules - snort arp scan detection -


hi new snort , simulated arp scan attack. trying detect attack in snort. no preprocessors detected attack wanted write rule it. find out snort rule not support arp protocol.

this scan sending arp request on possible addresses subnet 192.168.92.0/24 , waits answer means host up. possible detect these attack using snort rules?

here example of scan wireshark.

arp scan in wireshark


Comments

Popular posts from this blog

php - Wordpress website dashboard page or post editor content is not showing but front end data is showing properly -

How to get the ip address of VM and use it to configure SSH connection dynamically in Ansible -

javascript - Get parameter of GET request -