This section explains Snort non-payload rule options.
flags
Use this if you want the Sensor to check for TCP flags. You can check for the following flags:
F - FIN (LSB in TCP Flags byte)
S - SYN
R - RST
P - PSH
A - ACK
U - URG
1 - Reserved bit 1 (MSB in TCP Flags byte)
2 - Reserved bit 2
0 - No TCP Flags Set
You can apply the following operators on the flags option:
+ — Checks if all the specified flags are set
* — Checks if at least one of the specified flags is set
! — Checks if none of the flags are set
Syntax: flags:[!|*|+]<FSRPAU120>[,<FSRPAU120>];
Example rule:
alert tcp 10.1.1.1 any -> any any (msg:"example for flags"; flags:R; sid:2019; priority:3;)
This rule raises an alert when the host 10.1.1.1 resets a TCP connection.
flow
This option enables you to write rules specific to a direction of the traffic flow. For example, you can write a rule that the Sensor applies only on the traffic from the clients.
The following table describes the flow options that you can use in Trellix IPS:
Option | Description |
|---|---|
| Rule is applicable only to the response traffic from the server in a TCP session. |
| Rule is applicable only to the request traffic from the client in a TCP session. |
| Same as to_server |
| Same as to_client |
Syntax: flow: [,(to_client|to_server|from_client|from_server)];
Example rule:
alert tcp !$HOME_NET any -> 10.1.1.1 80 (msg:"example for flow"; flow:to_server; content:"cmd.exe";sid:2015; priority:1;)
For this rule, the Sensor checks for cmd.exe in the request traffic from outside network to 10.1.1.1.
Notes:
Make sure you specify the flow option in the Snort custom attacks to avoid false-positives.
If you do not specify flow for a TCP rule, then it is saved in the Manager with Conversion Result, "warning" and State Published.
itype
Use this if the Sensor is to check for a specific ICMP type value.
Syntax: itype:[<|>]<number>[<><number>];
icode
Use this if the Sensor is to check for a specific ICMP code value.
Syntax: icode: [<|>]<number>[<><number>];
Example rule:
alert icmp !$HOME_NET any -> $HOME_NET any (msg:"example for itype and icode"; itype 8; icode:0; sid:2022; priority:3;)
This rule is triggered for inbound traffic where the type is 8 and code is 0.
icmp_seq
This is to check for a specific ICMP sequence value.
Syntax: icmp_seq:<number>;
Example rule:
alert icmp !$HOME_NET any -> $HOME_NET any (msg:"example for icmp_seq"; icmp_seq:0; sid:2041; priority:3;)