更新时间:2022-12-22 12:57:44
我建议您为此使用错误的事件. file_timeout
仅在发生文件传输然后停止但未完成的情况下发生.一个更有趣的事件关联是:
I would suggest that you're using the wrong event for this. The file_timeout
only occurs if a file transfer was occurring and then stopped without completing. A much more interesting event correlation would be:
event
dns_A_reply(c: connection, msg: dns_msg, ans: dns_answer, a:
addr)
). orig_h
是内部的
地址)id$resp_h
中的地址是否在的集合中
解决步骤2.如果是,则返回,如果不是,则返回
产生通知,因为您尝试进行出站连接
没有相应的DNS查找.event
dns_A_reply(c: connection, msg: dns_msg, ans: dns_answer, a:
addr)
). orig_h
on the SYN is an internal
address)id$resp_h
is in the set of
addresses step 2. If it is, return, if it isn't,
generate a notice since you have an outbound connection attempt with
no corresponding DNS lookup.