This section explains how to construct Snort rules that can detect TCP, UDP, or ICMP communication between specific hosts or networks based on IP address.
Note
To detect TCP, UDP and ICMP communication between a set of IP addresses, you must create 3 separate rules.
TCP communication
To detect TCP communication between hosts specify ip_proto:tcp; and flags:S as the attack parameters.
Example:
alert tcp 10.1.1.10 any -> [192.168.230.0/24, 192.168.231.0/24] any (msg:”Malicious TCP Traffic”;ip_proto:tcp;flags:S;sid:3121;)
Here 10.1.1.10 is an example source IP and [192.168.230.0/24, 192.168.231.0/24] are the example destination subnets.
If you do not specify flag:S the rule is triggered for all the TCP packets between the specified hosts.
UDP communication
To detect UDP communication between hosts, specify ip_proto:udp; as the attack parameter.
Example:
alert udp 10.1.1.10 any -> [192.168.230.0/24, 192.168.231.0/24] any (msg:”Malicious UDP Traffic”;ip_proto:udp;sid:3122;)
Here 10.1.1.10 is an example source IP and [192.168.230.0/24, 192.168.231.0/24] are the example destination subnets. The Sensor sends alerts for any UDP packet detected between the specified hosts.
ICMP communication
To detect ICMP communication between hosts, specify ip_proto:icmp; as the attack parameter.
Example:
alert ip 10.1.1.10 any -> [192.168.230.0/24, 192.168.231.0/24] any (msg:”Malicious ICMP Traffic”;ip_proto:icmp;sid:3123;)
Here 10.1.1.10 is an example source IP and [192.168.230.0/24, 192.168.231.0/24] are the example destination subnets.
In the rule, use the following parameters along with icmp for a more specific detection:
itype - Use this to check for a specific ICMP type value
Syntax: itype:[<|>]<number>[<><number>];
icode - Use this to check for a specific ICMP code value.
Syntax: icode: [<|>]<number>[<><number>];
Example:
alert icmp 10.1.1.10 any -> [192.168.230.0/24, 192.168.231.0/24] any (msg:"example for itype and icode"; itype 8; icode:0; sid:2022; priority:3;)
Here 10.1.1.10 is an example source IP and [192.168.230.0/24, 192.168.231.0/24] are the example destination subnets. This rule is triggered for inbound traffic where the type is 8 and code is 0.