6.2 1000 Series—IP Signatures
6.2.3 IP option signatures
The following are IP Option signatures:
  • 1000—Bad option list (severity 1, information): This signature is triggered by receipt of an IP datagram where the list of IP options in the IP datagram header is incomplete or malformed. No known exploits purposely incorporate this option. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain or that poorly written hacker code may produce malformed datagrams.
  • 1001—Record packet route (severity 1, information/reconnaissance): This signature is triggered by receipt of an IP datagram where the IP option list for the datagram includes option 7 (Record Packet Route). This alarm may indicate a reconnaissance attack is in progress against your network.
  • 1002—Timestamp (severity 1, information): This signature is triggered by receipt of an IP datagram where the IP option list for the datagram includes option 4 (Timestamp). This alarm indicates that a reconnaissance attack may be in progress against your network.
  • 1003—Provide s, c, h, and tcc (severity 1, information): This signature is triggered by receipt of an IP datagram where the IP option list for the datagram includes option 2 (Security options). No known exploit exists. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 1004—Loose source route (severity 5, access): This signature is triggered by receipt of an IP datagram where the IP option list for the datagram includes option 3 (Loose Source Route). This option may be misused to defeat authentication mechanisms that rely on IP addresses as their basis for trust relationships.
  • 1005—SATNET id (severity 1, information): This signature is triggered by receipt of an IP datagram where the IP option list for the datagram includes option 8 (SATNET stream identifier). This signature is included for completeness. No known exploit exists. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 1006—Strict source route (severity 5, access): This signature is triggered by receipt of an IP datagram in which the IP option list for the datagram includes option 2 (Strict Source Routing). This option may be misused to defeat authentication mechanisms that rely on IP addresses as their basis for trust relationships. The limited number of routes that may be stored in the options field minimize the usefulness of this option as a mode of attack across large Internets.