The following are ICMP Attack signatures:
-
- 2150—Fragmented ICMP packet
(severity 5, access/DoS): This signature is triggered when an IP
datagram is received with the protocol field of the IP header set
to 1 (ICMP) and either the more fragments flag is set to 1 (ICMP)
or there is an offset indicated in the offset field. The Boolean
equation that describes this as ICMP AND (MFFLAG OR OFFSET).
Fragmented ICMP traffic may indicate a DoS attempt.
- 2151—Large ICMP packet (severity
5, DoS): This signature is triggered when an IP datagram is
received with the protocol field of the IP header set to 1(ICMP)
and the IP length set to a value greater than 1024. A large ICMP
packet may indicate a DoS attack.
- 2152—ICMP Flood (severity 5, DoS):
This signature is triggered when multiple IP datagrams are
received directed at a single host on the network with the
"protocol" field of the IP header set to 1 (ICMP). This
indicates that a DoS attack may be in progress against your
network.
- 2153—ICMP Smurf attack (severity
5, DoS): This signature is triggered when a large number of ICMP
Echo Replies is targeted at a machine. They can be from one or
many sources. This will catch the attack known as Smurf, described
in the related vulnerability page. Since this attack can come from
many sources, automatic shunning of individual hosts is not very
effective. If only one network is being used to broadcast the
replies, the network can be shunned.
- 2154—-ICMP Ping Of Death (severity
5, DoS): This signature is triggered when an IP datagram is
received with the protocol field of the IP header set to 1 (ICMP),
the Last Fragment bit is set, and (IP offset * 8 ) + ( IP data
length) > 65535 that is to say, the IP offset (which represents
the starting position of this fragment in the original packet, and
which is in 8 byte units) plus the rest of the packet is greater
than the maximum size for an IP packet. This indicates a DoS
attack.
|
|