6.4 3000 Series—TCP Signatures
6.4.4 TCP Port Scan signatures
The following are TCP Port Scan signatures: -
  • 3001—Port Sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP connections to a number of different privileged ports (having port number less than 1024) on a specific host have been initiated. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack. This is a catchall signature, which will fire if the specific type of TCP Port Sweep cannot be determined.
  • 3002—SYN Port Sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP SYN packets have been sent to a number of different destination ports on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack.
  • 3003—Frag SYN Port Sweep (severity 5, reconnaissance): This signature is triggered when a series of fragmented TCP SYN packets are sent to a number of different destination ports on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. The fragmentation indicates an attempt to conceal the sweep. This may be the prelude to a more serious attack.
  • 3005—FIN port sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP FIN packets have been sent to a number of different privileged ports (having port number less than 1024) ports on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. The use of FIN packets indicates an attempt to conceal the sweep. This may be the prelude to a more serious attack.
  • 3006—Frag FIN port sweep (severity 5, reconnaissance): This signature is triggered when a series of fragmented TCP FIN packets have been sent to a number of different privileged ports (having port number less than 1024) destination ports on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. The use of fragmentation and of FIN packets indicates an attempt to conceal the sweep. This may be the prelude to a more serious attack.
  • 3010—High port sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP connections to a number of different high-numbered ports (having port number greater than 1023) on a specific host have been initiated. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack. This is a catchall signature that will fire if the specific type of TCP Port Sweep cannot be determined.
  • 3011—FIN High port sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP FIN packets have been sent to a number of different destination high-numbered ports (having port number greater than 1023) on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. The use of FIN packets indicates an attempt to conceal the sweep. This may be the prelude to a more serious attack.
  • 3012—Frag High FIN port sweep (severity 5, reconnaissance): This signature is triggered when a series of fragmented TCP FIN packets have been sent to a number of different destination high-numbered ports (having port number greater than 1023) on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. The use of fragmentation and of FIN packets indicates an attempt to conceal the sweep. This may be the prelude to a more serious attack.
  • 3015—Null port sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP packets with none of the SYN, FIN, ACK, or RST flags set have been sent to a number of different destination ports on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. The use of this type of packet indicates an attempt to conceal the sweep. This may be the prelude to a more serious attack.
  • 3016—Frag Null port sweep (severity 5, reconnaissance): This signature is triggered when a series of fragmented TCP packets with none of the SYN, FIN, ACK, or RST flags set have been sent to a number of different destination ports on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. The use of this type of packet and of fragmentation indicates an attempt to conceal the sweep. This may be the prelude to a more serious attack.
  • 3020—SYN FIN port sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP packets with both the SYN and FIN flags set have been sent to a number of different destination ports on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. The use of both the SYN and FIN flag is abnormal, and could indicate an attempt to conceal the sweep. This may be the prelude to a more serious attack.
  • 3021—Frag SYN/FIN port sweep (severity 5, reconnaissance): This signature is triggered when a series of fragmented TCP packets with both the SYN and FIN flags set have been sent to a number of different destination ports on a specific host. This is indicative that a reconnaissance sweep of your network may be in progress. The use of both the SYN and FIN flag is abnormal, as is the use of fragmentation, and could indicate an attempt to conceal the sweep. This may be the prelude to a more serious attack.
  • 3045—Queso sweep (severity 5, reconnaissance): This signature is triggered after having detected a FIN, SYN-FIN, and a PUSH sent from a specific host bound for a specific host.