The following are SYN Flood and TCP Hijack
signatures:
- 3050—Half-Open SYN attack
(severity 5, DoS): This signature is triggered when multiple TCP
sessions have been improperly initiated on any of several
well-known service ports. Detection of this signature is currently
limited to FTP, Telnet, WWW, and E-mail servers (TCP ports 21, 23,
80 and 25 respectively). This is indicative that a DoS attack
against your network may be in progress.
- 3250—TCP Hijacking (severity 5,
access): This signature is triggered when both streams of data
within a TCP connection indicate that a TCP hijacking may have
occurred. The current implementation of this signature does not
detect all types of TCP hijacking and false positives may occur.
Even when hijacking is discovered, little information is available
to the operator other than the source and destination addresses
and ports of the systems being affected. TCP Hijacking may be used
to gain illegal access to system resources.
- 3251—TCP Hijacking Simplex Mode
(severity 5, access): This signature is triggered when both
streams of data within a TCP connection indicate that a TCP
hijacking may have occurred. The current implementation of this
signature does not detect all types of TCP hijacking and false
positives may occur. Even when hijacking is discovered, little
information is available to the operator other than the source and
destination addresses and ports of the systems being affected. TCP
Hijacking may be used to gain illegal access to system resources.
Simplex mode means that only one command is sent, followed by a
connection RESET packet, which makes recognition of this signature
different from regular TCP Hijacking (sigID 3250).
|
|