rules - snort arp scan detection -


hi new snort , simulated arp scan attack. trying detect attack in snort. no preprocessors detected attack wanted write rule it. find out snort rule not support arp protocol.

this scan sending arp request on possible addresses subnet 192.168.92.0/24 , waits answer means host up. possible detect these attack using snort rules?

here example of scan wireshark.

arp scan in wireshark


Comments

Popular posts from this blog

authentication - Mongodb revoke acccess to connect test database -

python - GitPython: check if git is available -

How to merge four videos on one screen with ffmpeg -