Comprehensive Guide to Signature Alert Classification: TCP, ICMP, UDP, and Data Protocol Insights


Signature alert classification

 
sig_class_id: Classification ID  
sig_class_name: Classification Name

Signature alert classification information.

iphdr

Signature alert classification

tcphdr

udphdr

icmphdr

data

 
data_payload: Packet Payload

When the protocol in the rule is TCP, data_payload contains the content after the TCP segment.

When the protocol in the rule is ICMP, data_payload contains the value of the data field in the ICMP protocol.

opt