6.7 6000 Series—Cross-Protocol Signatures
6.7.9 Distributed denial of service attack signatures
A distributed denial of service (DDoS) attack is a form of a DoS attack where the attack launched against a victim host or network is launched from multiple attacking hosts. The attacking hosts are controlled from a master host. The following are DDoS Attack signatures:
  • 6501—TFN Client request (severity 5, DoS): Tribe Flood Network (TFN) is a distributed DoS tool. This signature looks for ICMP echo reply packets containing potential TFN commands sent from a TFN CLIENT--TO-> a SERVER. The ICMP reply will not have an associated ICMP echo request packet. Other associated signatures: TFN Server Reply, detects server sending packets to client. Loki ICMP tunneling, which can also detect TFN traffic.
  • 6502—TFN Server reply (severity 5, DoS): Tribe Flood Network (TFN) is a distributed DoS tool. This signature looks for ICMP echo reply packets containing potential TFN commands sent from a TFN CLIENT>TO > a SERVER. The ICMP reply will not have an associated ICMP echo request packet. Other associated signatures: TFN Server Reply, detects server sending packets to client. Loki ICMP tunneling, which can also detect TFN traffic.
  • 6503—Stacheldraht Client request (severity 5, DoS): Stacheldraht clients and servers by default, communicate using ICMP echo reply packets. This signature looks for ICMP echo reply packets containing potential commands sent from a Stacheldraht CLIENT > TO > SERVER. The ICMP reply will not have an associated ICMP echo request packet. Other associated signatures: Stacheldraht Server Reply, detects server sending packets to client. Loki ICMP tunneling, which can also detect Stacheldraht traffic. Large ICMP Traffic, detects a reported bug in the Stacheldraht code that sends out large >1000 byte packets.
  • 6504—Stacheldraht Server reply(severity 5, DoS): Stacheldraht clients and servers by default, communicate using ICMP echo reply packets. This signature looks for ICMP echo reply packets containing potential commands sent from a Stacheldraht CLIENT --TO--> SERVER. The ICMP reply will not have an associated ICMP echo request packet. Other associated signatures: Stacheldraht Server Reply, detects server sending packets to client. Loki ICMP tunneling, which can also detect Stacheldraht traffic. Large ICMP Traffic , detects a reported bug in the Stacheldraht code that sends out large >1000 byte packets.
  • 6505—Trinoo Client request (severity 5, DoS): Trinoo clients communicate by default on UDP port 27444 using a default command set. This signature looks for UDP packets containing potential commands from a Trinoo CLIENT >TO> SERVER.
  • 6506—Trinoo Server reply (severity 5, DoS): Trinoo clients communicate by default on UDP port 27444 using a default command set. This signature looks for UDP packets containing potential commands from a Trinoo CLIENT>TO> SERVER.
  • 6507—TFN2K DDoS Control traffic (severity 5, DoS): TFN2K is a more robust and flexible version of the original Tribe Flood Network. This signature identifies the control traffic from the hackers client console and the server (zombie) machine.
  • 6508—mstream DDoS Control traffic (severity 5, DoS): Mstream is a Unix based distributed DoS tool similar to Trinoo, TFN and Stacheldraht. Mstream uses the Stream (stream.c) DoS as its method of assault. This signature identifies the control traffic between both the attacker <-> client (aka handler), and between the client (aka handler) <-> server (aka agent or daemon).