--- /dev/null
+reject tcp any any -> any any (msg: "Bad keyword detected!"; content: "ultrasurf"; http_uri; sid: 1;)
+alert tcp any any -> any any (msg:"SURICATA STREAM suspected RST injection"; stream-event:suspected_rst_inject; classtype:protocol-command-decode; sid:2210058; rev:1;)
--- /dev/null
+args:
+- -k none
+
+checks:
+ - filter:
+ count: 2
+ match:
+ event_type: alert
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2210058
+ - filter:
+ count: 1
+ match:
+ event_type: http
+ http.url: /ultrasurf.html
--- /dev/null
+reject tcp any any -> any any (content: "/"; http_uri; startswith; endswith; sid: 1;)
+alert tcp any any -> any any (msg:"SURICATA STREAM suspected RST injection"; stream-event:suspected_rst_inject; classtype:protocol-command-decode; sid:2210058; rev:1;)
--- /dev/null
+args:
+- -k none
+
+checks:
+ - filter:
+ count: 2
+ match:
+ event_type: alert
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 1
+ - filter:
+ count: 1
+ match:
+ event_type: alert
+ alert.signature_id: 2210058
+ - filter:
+ count: 1
+ match:
+ event_type: http
+ http.url: /