snort local rules
Add rules to catch the traffic listed below. On the security onion these rules would typically be placed in the /etc/nsm/rules/local.rules file. The action for these rules should be a message with “Defense class” in it.
Any DNS traffic for the domain “xkcd.com”.
Traffic going to 192.168.13.37 containing the phrase “Hello World”.
Any traffic that contains the HEX pattern “57 54” and HEX pattern “42 55 46 46 53” found within 9 bytes of the end of the first pattern.
Turn in the three rules that you created as an attached file.
If you wish to test your rules you will have to load the rules into the set of rules that snort is looking for. This can happen with running the following command: sudo rule-update
Do you need a similar assignment done for you from scratch? We have qualified writers to help you. We assure you an A+ quality paper that is free from plagiarism. Order now for an Amazing Discount!
Use Discount Code "Newclient" for a 15% Discount!
NB: We do not resell papers. Upon ordering, we do an original paper exclusively for you.

