Blog | G5 Cyber Security

New SO Rules For Conficker.C P2P Detection

Snort preprocessor developed to detect P2P traffic being used by Conficker.C to distribute updates and the like. Two SO rules (one for TCP and another for UDP) appear to be extremely effective. For a single PCAP that spans 25 hours, 47,450 alerts are generated by the UDP rule; another 37,541 by the TCP rule. Anyone using these rules should tune the “seconds” parameter to a longer value if they want fewer alerts, and of course update the sig_id to reflect the SID they use to deploy these rules in their environment.”]

Source: https://blog.talosintelligence.com/2009/04/new-so-rules-for-confickerc-p2p.html

Exit mobile version