As per the title, I'm attempting to configure Snort to detect and alert on a incoming Denial of Service attack.
Looking at the rulesets, which are primarily signature based rules, I can't see a logical way of looking for a flood of SYN ACK packets?
I've seen some of the examples from the following link, but they appear to be mostly anonmalay based examples (What approaches are to detect DoS attack in IDS/Firewall?) - I'm wondering if there's a rule available to detect such an attack.
Thanks!