6.4 3000 Series—TCP Signatures
6.4.12 SYN Flood and TCP Hijack signatures
The following are SYN Flood and TCP Hijack signatures:
  • 3050—Half-Open SYN attack (severity 5, DoS): This signature is triggered when multiple TCP sessions have been improperly initiated on any of several well-known service ports. Detection of this signature is currently limited to FTP, Telnet, WWW, and E-mail servers (TCP ports 21, 23, 80 and 25 respectively). This is indicative that a DoS attack against your network may be in progress.
  • 3250—TCP Hijacking (severity 5, access): This signature is triggered when both streams of data within a TCP connection indicate that a TCP hijacking may have occurred. The current implementation of this signature does not detect all types of TCP hijacking and false positives may occur. Even when hijacking is discovered, little information is available to the operator other than the source and destination addresses and ports of the systems being affected. TCP Hijacking may be used to gain illegal access to system resources.
  • 3251—TCP Hijacking Simplex Mode (severity 5, access): This signature is triggered when both streams of data within a TCP connection indicate that a TCP hijacking may have occurred. The current implementation of this signature does not detect all types of TCP hijacking and false positives may occur. Even when hijacking is discovered, little information is available to the operator other than the source and destination addresses and ports of the systems being affected. TCP Hijacking may be used to gain illegal access to system resources. Simplex mode means that only one command is sent, followed by a connection RESET packet, which makes recognition of this signature different from regular TCP Hijacking (sigID 3250).