Creating custom IPS rules
Hi,
I am trying to create a custom IPS rule to restrict TCP sessions by size.
I couldn’t find any way of defining the proper context for such a rule.
My scenario is – any single session should be terminated when over ‘X’ amount of data was transmitted on this session (especially SSL sessions).
Did anyone configure something of this sort? Is it possible? Considering the context of the signature should be ‘session’ and not a specific field.
Thanks.
