6.3 2000 Series—ICMP Signatures
6.3.7 ICMP attack signatures
The following are ICMP Attack signatures: -
  • 2150—Fragmented ICMP packet (severity 5, access/DoS): This signature is triggered when an IP datagram is received with the protocol field of the IP header set to 1 (ICMP) and either the more fragments flag is set to 1 (ICMP) or there is an offset indicated in the offset field. The Boolean equation that describes this as ICMP AND (MFFLAG OR OFFSET). Fragmented ICMP traffic may indicate a DoS attempt.
  • 2151—Large ICMP packet (severity 5, DoS): This signature is triggered when an IP datagram is received with the protocol field of the IP header set to 1(ICMP) and the IP length set to a value greater than 1024. A large ICMP packet may indicate a DoS attack.
  • 2152—ICMP Flood (severity 5, DoS): This signature is triggered when multiple IP datagrams are received directed at a single host on the network with the "protocol" field of the IP header set to 1 (ICMP). This indicates that a DoS attack may be in progress against your network.
  • 2153—ICMP Smurf attack (severity 5, DoS): This signature is triggered when a large number of ICMP Echo Replies is targeted at a machine. They can be from one or many sources. This will catch the attack known as Smurf, described in the related vulnerability page. Since this attack can come from many sources, automatic shunning of individual hosts is not very effective. If only one network is being used to broadcast the replies, the network can be shunned.
  • 2154—-ICMP Ping Of Death (severity 5, DoS): This signature is triggered when an IP datagram is received with the protocol field of the IP header set to 1 (ICMP), the Last Fragment bit is set, and (IP offset * 8 ) + ( IP data length) > 65535 that is to say, the IP offset (which represents the starting position of this fragment in the original packet, and which is in 8 byte units) plus the rest of the packet is greater than the maximum size for an IP packet. This indicates a DoS attack.