You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:Snort规则无法捕获从互联网下载的JPG文件

Troubleshooting Your Snort JPG Detection Rule

Hey there! Let's dig into why your Snort rule isn't picking up those JPG downloads from the internet. I've worked through similar issues before, so here are the key fixes and checks to get your rule working:

1. Correct the Traffic Direction

Your current rule uses <> which matches bidirectional TCP traffic, but JPG downloads are one-way: from an external server to your internal network ($HOME_NET). Switching to -> ensures you're only targeting the inbound download flow, avoiding false positives or irrelevant matches:

alert tcp any any -> $HOME_NET any (msg:"JPEG Download Detected"; content:"|FF D8 FF E0|"; sid:1000001)

2. Narrow Down to HTTP/HTTPS Ports (and Handle Encryption)

JPGs are almost always transferred over HTTP (port 80) or HTTPS (port 443). Limiting the source ports makes your rule more efficient and targeted:

alert tcp any [80,443] -> $HOME_NET any (msg:"JPEG Download Detected"; content:"|FF D8 FF E0|"; sid:1000001)

Critical Note: If you're dealing with HTTPS traffic, Snort can't see the JPEG content unless you've set up SSL/TLS decryption (e.g., using a MITM certificate or integrating with a TLS proxy). Encrypted traffic hides the payload, so your content match will fail without decryption enabled.

3. Add Context for HTTP Response Bodies

The JPEG data lives in the HTTP response body, not the request headers. Adding the http_body keyword tells Snort to focus only on that part of the stream. Pair it with flow:to_client,established to ensure you're looking at active, server-to-client connections (where downloads happen):

alert tcp any [80,443] -> $HOME_NET any (msg:"JPEG Download Detected"; content:"|FF D8 FF E0|"; http_body; flow:to_client,established; sid:1000001)

4. Cover More JPEG Variations

Not all JPEGs start with FF D8 FF E0—many use FF D8 FF E1 (for EXIF data) or other APP markers. To catch more cases, adjust your content match to target the universal JPEG start (FF D8) plus any following FF marker:

alert tcp any [80,443] -> $HOME_NET any (msg:"JPEG Download Detected"; content:"|FF D8|"; offset:0; depth:2; content:"|FF|"; offset:2; depth:1; http_body; flow:to_client,established; sid:1000001)

This checks for the mandatory JPEG header, then ensures the next byte is an FF (the start of all JPEG segments), covering most JPEG variants.

Start with these adjustments—test the rule with a clear HTTP JPG download first (to avoid HTTPS encryption issues) and you should start seeing alerts!

内容的提问来源于stack exchange,提问作者Leetm

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 06:20:48