01-03-2011 12:40 PM - edited 03-10-2019 05:13 AM
I am trying to monitor TOR Client Activity via SIG IDs 5816/1 and 5816/0, however the IPS doesn't seem to pick them up. I watch the logs while running TOR from a test machine and I see nothing. Is there something I am missing or doing wrong? Both are enabled in the the Policy that I am using on the IPS Sensors.
Thanks in Advance!
Jeremy
Solved! Go to Solution.
01-06-2011 04:36 AM
Jeremy;
You will most likely need to perform a packet capture of the initial TOR connection traffic and analyze that it meets the signature specifics:
If the above criteria are not present in the traffic your TOR client is using, the IPS will not detect the activity.
Scott
01-06-2011 04:36 AM
Jeremy;
You will most likely need to perform a packet capture of the initial TOR connection traffic and analyze that it meets the signature specifics:
If the above criteria are not present in the traffic your TOR client is using, the IPS will not detect the activity.
Scott
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide