Beispiel #1
0
 def _make_rule(self, content, uricontent, dst_port, sid=0):
     rule = SnortRule()
     pattern = dict()
     pattern['msg'] = '"Trojan.Gen.uricontent"'
     pattern['content'] = ['"{host}"'.format(host=content), 'nocase']
     pattern['uricontent'] = ['"{uri}"'.format(uri=uricontent), 'nocase']
     # pattern['sid'] = sid
     pattern['dst_port'] = dst_port
     rule.set_malicious_pattern(**pattern)
     return rule
Beispiel #2
0
 def _make_rule(self, content, uricontent, dst_port, sid=0):
     rule = SnortRule()
     pattern = dict()
     pattern['msg'] = '"Trojan.Gen.uricontent"'
     pattern['content'] = ['"{host}"'.format(host=content), 'nocase']
     pattern['uricontent'] = ['"{uri}"'.format(uri=uricontent), 'nocase']
     # pattern['sid'] = sid
     pattern['dst_port'] = dst_port
     rule.set_malicious_pattern(**pattern)
     return rule