SNORT 룰 질문 드립니다.

dw0291kim의 이미지

For IDS(Intrusion Detection System), you are to implement SNORT to detect intrusion to your system.
As an added security, any ping packets greater than 650 bytes should be detected

대충 한글로 이해하면 IDS를 위해 SNORT를 깔고 650바이트 이상의 PING을 감지하라는데요

이건 제가 룰을 만들어 줘야 하는건가요

SNORT룰을 만드는 자료는 찾아보질 못해서요,,,.