1

I'm new to snort. I'm trying to set up rules in snort to detect the presence of covert timing channels. Ideally, I would like to use pre-made rules like the snort community rules.

So far, I've found the snort community ruleset and the emerging threats ruleset but I couldn't find anything specific to timing covert channel attacks.

1
  • That's because the rule set would have to be hyper-specific to the type of system that you would have. There's not going to be a specific rule set for that.
    – schroeder
    Commented Jun 25 at 11:17

0

You must log in to answer this question.

Browse other questions tagged .