next up previous contents
Next: Format Up: Non-Payload Detection Rule Options Previous: Example   Contents


The id keyword is used to check the IP ID field for a specific value. Some tools (exploits, scanners and other odd programs) set this field specifically for various purposes, for example, the value 31337 is very popular with some hackers.


Eugene Misnik 2013-05-08