Skip to content

Latest commit

 

History

History
26 lines (19 loc) · 781 Bytes

icmp-anomaly-detection.rst

File metadata and controls

26 lines (19 loc) · 781 Bytes

ICMP Anomaly Detection

At Security Onion Conference 2016, Eric Conrad shared some IDS rules for detecting unusual ICMP echo requests/replies and identifying C2 channels that may utilize ICMP tunneling for covert communication.

Usage

We can add the rules to /etc/nsm/rules/local.rules and the variables to snort.conf and/or suricata.yaml so that we can gain better insight into ICMP echoes or replies over a certain size, containing particularly suspicious content, etc.

Presentation

Download