High Volume UDP Connections from a Single Process

This rule detects a high volume of UDP network connections originating from a single process on a device. A count exceeding 50 UDP connections from the same process to the same remote IP address is considered anomalous and could indicate a UDP flood or other denial-of-service attempt.