Hi, guys,I need your swarm intelligence.
I'm supposed to write a use case that detects a very specific traffic pattern.
Specifically, this is about an SRC system sending a packet to a destination system on destination port 161 and within 10 minutes this destination system sends a "response" "connection" to another system on destination port 69. Here the 2nd destination system can be the 1st SRC system or another.
I can't get a real transaction here because there is no identifier except that the 1st destination system becomes the SRC system.
I thank you for your time and effort!