We present a way to detect a type of denial of service (DoS) flood attack within the network. For this example, the attack is within the network and is directed at another machine on the internal network.
Snort acts as an IPS when it detects that an attack is taking place within the network, alerts and then blocks the attacker's address. In this scenario Pfsense is on the way to the Internet, so a machine on the blocked internal network is prevented from accessing the Internet.
Professor Dalbert
#Snort #Pfsense #DoS
Snort rule to detect DoS:
English:
https://simplificandoredes.com/en/sno...
Português:
https://simplificandoredes.com/snort-...
00:00 Start
00:15 Card with video about the attack
00:56 Configuration
04:00 Creating the rule to detect DoS
09:55 Starting the DoS tool for testing
10:30 Checking Snort Alerts