The following are TCP Host Sweeps
Signatures:
- 3030—SYN host sweep (severity 1,
reconnaissance): This signature is triggered when a series of TCP
SYN packets have been sent to the same destination port on a
number of different hosts. This could, for example, be a sweep of
many hosts to find out which ones can receive mail or telnet
sessions. This is indicative that a reconnaissance sweep of your
network may be in progress. This may be the prelude to a more
serious attack.
- 3031—Frag SYN host sweep (severity
5, reconnaissance): This signature is triggered when a series of
fragmented TCP SYN packets have been sent to the same destination
port on a number of different hosts. This could, for example, be a
sweep of many hosts to find out which ones can receive mail or
telnet sessions. This is indicative that a reconnaissance sweep of
your network may be in progress. This may be the prelude to a more
serious attack. The use of fragmentation is abnormal and could
indicate an attempt to conceal the sweep.
- 3032—FIN host sweep (severity 5,
reconnaissance): This signature is triggered when a series of TCP
FIN packets have been sent to the same destination port on a
number of different hosts. This could, for example, be a sweep of
many hosts to find out which ones can receive mail or telnet
sessions. This is indicative that a reconnaissance sweep of your
network may be in progress. This may be the prelude to a more
serious attack.
- 3033—Frag FIN host sweep (severity
5, reconnaissance): This signature is triggered when a series of
TCP FIN packets have been sent to the same destination port on a
number of different hosts. This could, for example, be a sweep of
many hosts to find out which ones can receive mail or telnet
sessions. This is indicative that a reconnaissance sweep of your
network may be in progress. This may be the prelude to a more
serious attack. The use of fragmentation is abnormal and could
indicate an attempt to conceal the sweep.
- 3034—NULL host sweep (severity 5,
reconnaissance): This signature is triggered when a series of TCP
packets with none of the SYN, FIN, ACK, or RST flags set have been
sent to the same destination port on a number of different hosts.
This could, for example, be a sweep of many hosts to find out
which ones can receive mail or telnet sessions. This is indicative
that a reconnaissance sweep of your network may be in progress.
This may be the prelude to a more serious attack. The use of this
packet is abnormal, and could indicate an attempt to conceal the
sweep.
- 3035—Frag NULL host sweep
(severity 5, reconnaissance): This signature is triggered when a
series of fragmented TCP packets with none of the SYN, FIN, ACK,
or RST flags set have been sent to the same destination port on a
number of different hosts. This could, for example, be a sweep of
many hosts to find out which ones can receive mail or telnet
sessions. This is indicative that a reconnaissance sweep of your
network may be in progress. This may be the prelude to a more
serious attack. The use of this packet is abnormal, as is the use
of fragmentation, and could indicate an attempt to conceal the
sweep.
- 3036—SYN/FIN host sweep (severity
5, reconnaissance): This signature is triggered when a series of
TCP packets with both the SYN and FIN flags set have been sent to
the same destination port on a number of different hosts. This
could, for example, be a sweep of many hosts to find out which
ones can receive mail or telnet sessions. This is indicative that
a reconnaissance sweep of your network may be in progress. The use
of both the SYN and FIN flag is abnormal, and could indicate an
attempt to conceal the sweep.
- 3037—Frag SYN/FIN host sweep
(severity 5, reconnaissance): This signature is triggered when a
series of TCP packets with both the SYN and FIN flags set have
been sent to the same destination port on a number of different
hosts. This could, for example, be a sweep of many hosts to find
out which ones can receive mail or telnet sessions. This is
indicative that a reconnaissance sweep of your network may be in
progress. This may be the prelude to a more serious attack. The
use of both the SYN and FIN flag is abnormal, as is the use of
fragmentation, and could indicate an attempt to conceal the sweep.
|
|