ScholarMatic | 24/7 Homework Help

ScholarMatic Will Help You Write Your Essays and Term Papers

Answered » You can buy a ready-made answer or pick a professional tutor to order an original one.

You have been investigating an apparent internal attack against your company’s Windows Server 2008 file servers. Suspicious packets have been…

by | Nov 28, 2023 | engineering

You have been investigating an apparent internal attack against your company’s Windows Server 2008 file servers. Suspicious packets have been captured during routine audits. You need to configure Snort to log these suspicious files. Your internal network address is 172.20.0.0 with a subnet mask of 255.240.0.0. Your file servers’ addresses are 172.20.0.12 and 172.20.0.13. Each of these file servers is running Snort as an HIDPS.

The suspicious packets have the following characteristics:

  • ? They have come from different systems inside your network.
  • ? The packets all include the word release between the 1000th and 1100th bytes.
  • ? The packets use TCP as their Transport layer protocol.
  • ? The packets appear to be trying to exploit vulnerabilities in the Windows implementation of SMB over IP.

You need to write a rule to be included in the rules directory of each server’s Snort installa- tion. These two rules must be as specific as possible so that the system logs only the packets that meet the signature of the suspicious network activity. The logged packets should be labeled as “Possible Internal SMB over IP Attack.” You must perform research beyond the scope of this chapter to find the needed information and create the rules. 

ScholarMatic: Explanation & Answer

Your ready answer from a verified tutor is just a click away for as little as $14.99


  

Click Order Now to get 100% Original Answer Customized to your instructions!

HOME TO CERTIFIED WRITERS

Why Place An Order With Us?

  • Certified Editors
  • 24/7 Customer Support
  • Profesional Research
  • Easy to Use System Interface
  • Student Friendly Pricing

Have a similar question?

PLAGIRAISM FREE PAPERS

All papers we provide are well-researched, properly formatted and cited.

TOP QUALITY

All papers we provide are well-researched, properly formatted and cited.

HIGHLY SECURED

All papers we provide are well-researched, properly formatted and cited.

ScholarMatic: Get Started

Assignment Writing Service

Feel safe and secure when placing an order on our portal!
Fruitful cooperation begins with solid guarantees, and we are professional enough to promise perfect results. Let’s get it started!

Open chat
1
Scan the code
ScholarMatic
Hello! Welcome to to our WhatsApp support.
We offer READY solutions, HIGH QUALITY PLAGIARISM FREE essays and term-papers.

We are online and ready to help