6.3 2000 Series—ICMP Signatures
6.3.3 ICMP query message signature
The following are ICMP Query Message signatures:
  • 2000—Echo Reply (severity 1, information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 0 (Echo Reply). ICMP Echo Replies have been used to bypass packet filter security policies as they are rarely filtered in either incoming or outgoing traffic. May be used to establish a communication channel or to perform DoS attacks.
  • 2004—Echo Request (severity 1, information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 8 (Echo Request). ICMP Echo Requests are commonly used to perform reconnaissance sweeps of networks. These sweeps often are a prelude to attack. Additionally they may be used to perform DoS attacks.
  • 2007—Timestamp Request (severity 1, reconnaissance/information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 13 (Timestamp Request). ICMP Timestamp Requests could be used to perform reconnaissance sweeps of networks. These sweeps often are a prelude to attack. Additionally they may be used to perform DoS attacks. No known exploits incorporate this option. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 2008—Timestamp Reply (severity 1, information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 14 (Timestamp Reply). ICMP Timestamp Replies could be used to perform DoS attacks. No known exploits incorporate this option. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 2009—Information Request (severity 1, information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 15 (Information Request). This signature is included for completeness. No known exploit exists. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 2010—Information Reply (severity 1, information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 16 (ICMP Information Reply). This signature is included for completeness. No known exploit exists. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 2011—Address Mask Request (severity 1, reconnaissance/information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 17 (Address Mask Request). ICMP Address Mask Requests could be used to perform reconnaissance sweeps of networks. These sweeps often are a prelude to attack. Additionally they may be used to perform DoS attacks. No known exploits incorporate this option. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.
  • 2012—Address Mask Reply (severity 1, information): This signature is triggered when an IP datagram is received with the "protocol" field of the IP header set to 1 (ICMP) and the "type" field in the ICMP header set to 18 (Address Mask Reply). ICMP Timestamp Replies could be used to perform DoS attacks. No known exploits incorporate this option. This does not preclude the possibility that exploits do exist outside of the realm of Cisco Systems' knowledge domain.