6.4 3000 Series—TCP Signatures
6.4.3 TCP Port Scans
TCP Port Scans are detected when a single host is searching for multiple running services on another single host—the victim. They are common scans that use normal TCP-SYN (connection request) to determine that a service is running. They are stealth scans use FIN; SYN-FIN; null; or PUSH flags, and fragmented packets, or both to determine that a service is running. The following is a TCP Flags refresher:
  • SYN—Synchronize sequence numbers to initiate a connection. Each time a new connection is established the SYN flag is turned on.
  • FIN—When set, this flag implies that the sender has finished sending data.
  • ACK—When the ACK field is on, the acknowledgment number in the corresponding field is valid. The acknowledgment number contains the next sequence number that the sender of the acknowledgment expects to receive.
  • RST—This flag is used to reset the TCP connection.
  • URG—The urgent pointer is valid when this flag is set. This pointer is a positive offset that must be added to the sequence number field of the segment to yield the sequence number of the last byte of urgent data.
  • PSH—Indicates that the receiver should pass this data to the application as soon as possible.