The following are TCP Port Scan
signatures:
-
- 3001—Port Sweep (severity 5,
reconnaissance): This signature is triggered when a series of TCP
connections to a number of different privileged ports (having port
number less than 1024) on a specific host have been initiated.
This is indicative that a reconnaissance sweep of your network may
be in progress. This may be the prelude to a more serious attack.
This is a catchall signature, which will fire if the specific type
of TCP Port Sweep cannot be determined.
- 3002—SYN Port Sweep (severity 5,
reconnaissance): This signature is triggered when a series of TCP
SYN packets have been sent to a number of different destination
ports on a specific host. This is indicative that a reconnaissance
sweep of your network may be in progress. This may be the prelude
to a more serious attack.
- 3003—Frag SYN Port Sweep (severity
5, reconnaissance): This signature is triggered when a series of
fragmented TCP SYN packets are sent to a number of different
destination ports on a specific host. This is indicative that a
reconnaissance sweep of your network may be in progress. The
fragmentation indicates an attempt to conceal the sweep. This may
be the prelude to a more serious attack.
- 3005—FIN port sweep (severity 5,
reconnaissance): This signature is triggered when a series of TCP
FIN packets have been sent to a number of different privileged
ports (having port number less than 1024) ports on a specific
host. This is indicative that a reconnaissance sweep of your
network may be in progress. The use of FIN packets indicates an
attempt to conceal the sweep. This may be the prelude to a more
serious attack.
- 3006—Frag FIN port sweep (severity
5, reconnaissance): This signature is triggered when a series of
fragmented TCP FIN packets have been sent to a number of different
privileged ports (having port number less than 1024) destination
ports on a specific host. This is indicative that a reconnaissance
sweep of your network may be in progress. The use of fragmentation
and of FIN packets indicates an attempt to conceal the sweep. This
may be the prelude to a more serious attack.
- 3010—High port sweep (severity 5,
reconnaissance): This signature is triggered when a series of TCP
connections to a number of different high-numbered ports (having
port number greater than 1023) on a specific host have been
initiated. This is indicative that a reconnaissance sweep of your
network may be in progress. This may be the prelude to a more
serious attack. This is a catchall signature that will fire if the
specific type of TCP Port Sweep cannot be determined.
- 3011—FIN High port sweep (severity
5, reconnaissance): This signature is triggered when a series of
TCP FIN packets have been sent to a number of different
destination high-numbered ports (having port number greater than
1023) on a specific host. This is indicative that a reconnaissance
sweep of your network may be in progress. The use of FIN packets
indicates an attempt to conceal the sweep. This may be the prelude
to a more serious attack.
- 3012—Frag High FIN port sweep
(severity 5, reconnaissance): This signature is triggered when a
series of fragmented TCP FIN packets have been sent to a number of
different destination high-numbered ports (having port number
greater than 1023) on a specific host. This is indicative that a
reconnaissance sweep of your network may be in progress. The use
of fragmentation and of FIN packets indicates an attempt to
conceal the sweep. This may be the prelude to a more serious
attack.
- 3015—Null port sweep (severity 5,
reconnaissance): This signature is triggered when a series of TCP
packets with none of the SYN, FIN, ACK, or RST flags set have been
sent to a number of different destination ports on a specific
host. This is indicative that a reconnaissance sweep of your
network may be in progress. The use of this type of packet
indicates an attempt to conceal the sweep. This may be the prelude
to a more serious attack.
- 3016—Frag Null port sweep
(severity 5, reconnaissance): This signature is triggered when a
series of fragmented TCP packets with none of the SYN, FIN, ACK,
or RST flags set have been sent to a number of different
destination ports on a specific host. This is indicative that a
reconnaissance sweep of your network may be in progress. The use
of this type of packet and of fragmentation indicates an attempt
to conceal the sweep. This may be the prelude to a more serious
attack.
- 3020—SYN FIN port sweep (severity
5, reconnaissance): This signature is triggered when a series of
TCP packets with both the SYN and FIN flags set have been sent to
a number of different destination ports on a specific host. This
is indicative that a reconnaissance sweep of your network may be
in progress. The use of both the SYN and FIN flag is abnormal, and
could indicate an attempt to conceal the sweep. This may be the
prelude to a more serious attack.
- 3021—Frag SYN/FIN port sweep
(severity 5, reconnaissance): This signature is triggered when a
series of fragmented TCP packets with both the SYN and FIN flags
set have been sent to a number of different destination ports on a
specific host. This is indicative that a reconnaissance sweep of
your network may be in progress. The use of both the SYN and FIN
flag is abnormal, as is the use of fragmentation, and could
indicate an attempt to conceal the sweep. This may be the prelude
to a more serious attack.
- 3045—Queso sweep (severity 5,
reconnaissance): This signature is triggered after having detected
a FIN, SYN-FIN, and a PUSH sent from a specific host bound for a
specific host.
|
|