求助:编写检测SMB共享访问的Suricata规则时,如何选择正确的app-layer-event参数?
Hey there! I get that you're trying to build a Suricata rule to catch attempts to access your SMB shares, and you're stuck figuring out the right app-layer-event value. Let me help you out with this—turns out you don't even need an app-layer event for this use case!
Why app-layer-event isn't the right fit here
The app-layer-event option is designed to trigger alerts on protocol parsing errors or abnormal events (like the smb.internal_error example you shared). For detecting legitimate SMB share access attempts, we should target the specific SMB commands that are used to connect to shares instead.
Working Rule Examples
SMB uses different commands depending on the version (SMBv1 vs SMBv2/v3). Here are tailored rules for each, plus a combined version:
- SMBv1 Share Connection Alert
alert smb any any -> $HOME_NET any (msg:"Attempt to access SMB Share (SMBv1)"; flow:to_server; smb.cmd:SMB_COM_TREE_CONNECT; classtype:attempted-recon; sid:1234567; rev:1;)
- SMBv2/v3 Share Connection Alert
alert smb any any -> $HOME_NET any (msg:"Attempt to access SMB Share (SMBv2/v3)"; flow:to_server; smb2.cmd:SMB2_TREE_CONNECT; classtype:attempted-recon; sid:1234568; rev:1;)
- Combined Rule for All SMB Versions
If you want to cover both SMBv1 and newer versions in one rule:
alert smb any any -> $HOME_NET any (msg:"Attempt to access SMB Share"; flow:to_server; (smb.cmd:SMB_COM_TREE_CONNECT or smb2.cmd:SMB2_TREE_CONNECT); classtype:attempted-recon; sid:1234567; rev:2;)
Key Notes
- Replace
$HOME_NETwith your actual internal network range (e.g.,192.168.1.0/24) to avoid alerting on traffic you don't care about. - The
classtype:attempted-reconfits here because connecting to a share is a form of network reconnaissance; you can adjust this to another classtype if it better matches your use case. - To check all supported SMB commands in your Suricata version, run this command in your terminal:
For SMBv2 commands, use:suricata --list-smb-cmdssuricata --list-smb2-cmds
This approach will reliably trigger alerts whenever someone tries to connect to your SMB shares, which is exactly what you're looking for!
内容的提问来源于stack exchange,提问作者cybel

