The following are IP Option signatures:
- 1000—Bad option list (severity 1,
information): This signature is triggered by receipt of an IP
datagram where the list of IP options in the IP datagram header is
incomplete or malformed. No known exploits purposely incorporate
this option. This does not preclude the possibility that exploits
do exist outside of the realm of Cisco Systems' knowledge domain
or that poorly written hacker code may produce malformed datagrams.
- 1001—Record packet route (severity
1, information/reconnaissance): This signature is triggered by
receipt of an IP datagram where the IP option list for the
datagram includes option 7 (Record Packet Route). This alarm may
indicate a reconnaissance attack is in progress against your
network.
- 1002—Timestamp (severity 1,
information): This signature is triggered by receipt of an IP
datagram where the IP option list for the datagram includes option
4 (Timestamp). This alarm indicates that a reconnaissance attack
may be in progress against your network.
- 1003—Provide s, c, h, and tcc
(severity 1, information): This signature is triggered by receipt
of an IP datagram where the IP option list for the datagram
includes option 2 (Security options). No known exploit exists.
This does not preclude the possibility that exploits do exist
outside of the realm of Cisco Systems' knowledge domain.
- 1004—Loose source route (severity
5, access): This signature is triggered by receipt of an IP
datagram where the IP option list for the datagram includes option
3 (Loose Source Route). This option may be misused to defeat
authentication mechanisms that rely on IP addresses as their basis
for trust relationships.
- 1005—SATNET id (severity 1,
information): This signature is triggered by receipt of an IP
datagram where the IP option list for the datagram includes option
8 (SATNET stream identifier). This signature is included for
completeness. No known exploit exists. This does not preclude the
possibility that exploits do exist outside of the realm of Cisco
Systems' knowledge domain.
- 1006—Strict source route (severity
5, access): This signature is triggered by receipt of an IP
datagram in which the IP option list for the datagram includes
option 2 (Strict Source Routing). This option may be misused to
defeat authentication mechanisms that rely on IP addresses as
their basis for trust relationships. The limited number of routes
that may be stored in the options field minimize the usefulness of
this option as a mode of attack across large Internets.
|
|