问题详情
如下哪个Snort规则头可用于检测源端口号高于1024的TCP数据报文()
A.alert tcp any :1024 -> any any
B.alert tcp any >1024 -> any any
C.alert udp any :1024 -> any any
D.alert tcp any 1024: -> any any
请帮忙给出正确答案和分析,谢谢!