6.4 3000 Series—TCP Signatures
6.4.6 TCP Host Sweeps signatures
The following are TCP Host Sweeps Signatures:
  • 3030—SYN host sweep (severity 1, reconnaissance): This signature is triggered when a series of TCP SYN packets have been sent to the same destination port on a number of different hosts. This could, for example, be a sweep of many hosts to find out which ones can receive mail or telnet sessions. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack.
  • 3031—Frag SYN host sweep (severity 5, reconnaissance): This signature is triggered when a series of fragmented TCP SYN packets have been sent to the same destination port on a number of different hosts. This could, for example, be a sweep of many hosts to find out which ones can receive mail or telnet sessions. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack. The use of fragmentation is abnormal and could indicate an attempt to conceal the sweep.
  • 3032—FIN host sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP FIN packets have been sent to the same destination port on a number of different hosts. This could, for example, be a sweep of many hosts to find out which ones can receive mail or telnet sessions. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack.
  • 3033—Frag FIN host sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP FIN packets have been sent to the same destination port on a number of different hosts. This could, for example, be a sweep of many hosts to find out which ones can receive mail or telnet sessions. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack. The use of fragmentation is abnormal and could indicate an attempt to conceal the sweep.
  • 3034—NULL host sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP packets with none of the SYN, FIN, ACK, or RST flags set have been sent to the same destination port on a number of different hosts. This could, for example, be a sweep of many hosts to find out which ones can receive mail or telnet sessions. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack. The use of this packet is abnormal, and could indicate an attempt to conceal the sweep.
  • 3035—Frag NULL host sweep (severity 5, reconnaissance): This signature is triggered when a series of fragmented TCP packets with none of the SYN, FIN, ACK, or RST flags set have been sent to the same destination port on a number of different hosts. This could, for example, be a sweep of many hosts to find out which ones can receive mail or telnet sessions. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack. The use of this packet is abnormal, as is the use of fragmentation, and could indicate an attempt to conceal the sweep.
  • 3036—SYN/FIN host sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP packets with both the SYN and FIN flags set have been sent to the same destination port on a number of different hosts. This could, for example, be a sweep of many hosts to find out which ones can receive mail or telnet sessions. This is indicative that a reconnaissance sweep of your network may be in progress. The use of both the SYN and FIN flag is abnormal, and could indicate an attempt to conceal the sweep.
  • 3037—Frag SYN/FIN host sweep (severity 5, reconnaissance): This signature is triggered when a series of TCP packets with both the SYN and FIN flags set have been sent to the same destination port on a number of different hosts. This could, for example, be a sweep of many hosts to find out which ones can receive mail or telnet sessions. This is indicative that a reconnaissance sweep of your network may be in progress. This may be the prelude to a more serious attack. The use of both the SYN and FIN flag is abnormal, as is the use of fragmentation, and could indicate an attempt to conceal the sweep.