The following are IP Fragmentation
signatures:
- 1100—IP Fragment Attack (severity
3, access): This signature is triggered when any IP datagram is
received with a small offset indicated in the offset field. This
indicates that the first fragment was unusually small, and is most
likely an attempt to defeat packet filter security policies.
- 1103—IP Fragments Overlap
(severity 5, DoS): Some implementations of the TCP/IP IP
fragmentation re-assembly code do not properly handle overlapping
IP fragments. Teardrop is a widely available attack tool that
exploits this vulnerability.
|
|