Recently I installed Snort on my Ubuntu server 18.04 And also wrote some rules in local.rules . it will perfectly detect my rules like ping , simple dos attacks etc.
I have 4 questions :
How can i block specific ip address , in Snort Detection rules ? (for example in dos detection rules)
Does Snort store any data about detection like IPs, contents etc. in some database ? with
apt-get install snort,mysqlhas been installed to .Is it possible to run a script on
alert?When i used
rejectaction and start snort inconsolemode , I got
connection refused
error on ssh , and cant login to ssh anymore until restart the server . The rule is :
reject tcp any any -> $HOME_NET any (msg:"simple dos attack"; threshold:type both, count 50 , seconds 5 , track by_dst ; sid:1000001 )