Table 28 Description of P-Series Snort Keywords

Keyword

Description

Rule Syntax

 

 

 

ttl

This keyword checks for the specified IP time-to-live

ttl: [number {><=} number-

 

value.

{-><=}] number;

 

 

 

uricontent

Searches the normalized request URI field for the

uricontent: [!] data_string”;

 

specified content.

 

 

data_string can contain mixed text and binary data.

 

 

Binary data is enclosed within pipe characters and is

 

 

written in hexadecimal form.

 

P-Series Installation and Operation Guide, version 2.3.1.2

121

Page 121
Image 121
Force10 Networks 100-00055-01 manual Ttl This keyword checks for the specified IP time-to-live, Uricontent ! datastring