6.1 Understanding Signatures
6.1.3 Signature classes
Reconnaissance class signatures are signatures that are triggered by a network activity that is known to be, or that could lead to, unauthorized discovery of systems, services, or vulnerabilities. Examples of reconnaissance activities are as follows:
  • Ping sweep
  • Port scan
  • DNS queries

Access class signatures are signatures that are triggered by a network activity that is known to be, or that could lead to, unauthorized data retrieval, system access, or privileged escalation. Examples of Access activities are as follows:

  • UNIX Tooltalk Database server attack
  • Internet Information Services (IIS) Unicode attack
  • Back Orifice or NetBus

Denial of service (DoS) class signatures are signatures that are triggered by network activity that is known to be, or that could lead to, the disablement or disruption of a network, system, or service. Examples of DoS activities are as follows:

  • Ping of Death
  • Tribe Flood Network (TFN) attacks
  • Trinoo attacks

Information class signatures are signatures that are triggered by normal network activity that in itself is not considered to be malicious, but can be used to determine the validity of an attack or for forensics purposes. Examples of information activities are as follows:

  • ICMP echo requests
  • TCP connection requests
  • UDP connections
Interactive Syntax Activity  (Flash, 177 Kb)
  In this activity you will practice identifying the various kinds of signatures and their purposes.