A distributed denial of service (DDoS)
attack is a form of a DoS attack where the attack launched against a
victim host or network is launched from multiple attacking hosts. The
attacking hosts are controlled from a master host. The following are
DDoS Attack signatures:
- 6501—TFN Client request (severity
5, DoS): Tribe Flood Network (TFN) is a distributed DoS tool. This
signature looks for ICMP echo reply packets containing potential
TFN commands sent from a TFN CLIENT--TO-> a SERVER. The ICMP
reply will not have an associated ICMP echo request packet. Other
associated signatures: TFN Server Reply, detects server sending
packets to client. Loki ICMP tunneling, which can also detect TFN
traffic.
- 6502—TFN Server reply (severity 5,
DoS): Tribe Flood Network (TFN) is a distributed DoS tool. This
signature looks for ICMP echo reply packets containing potential
TFN commands sent from a TFN CLIENT>TO > a SERVER. The ICMP
reply will not have an associated ICMP echo request packet. Other
associated signatures: TFN Server Reply, detects server sending
packets to client. Loki ICMP tunneling, which can also detect TFN
traffic.
- 6503—Stacheldraht Client request
(severity 5, DoS): Stacheldraht clients and servers by default,
communicate using ICMP echo reply packets. This signature looks
for ICMP echo reply packets containing potential commands sent
from a Stacheldraht CLIENT > TO > SERVER. The ICMP reply
will not have an associated ICMP echo request packet. Other
associated signatures: Stacheldraht Server Reply, detects server
sending packets to client. Loki ICMP tunneling, which can also
detect Stacheldraht traffic. Large ICMP Traffic, detects a
reported bug in the Stacheldraht code that sends out large
>1000 byte packets.
- 6504—Stacheldraht Server
reply(severity 5, DoS): Stacheldraht clients and servers by
default, communicate using ICMP echo reply packets. This signature
looks for ICMP echo reply packets containing potential commands
sent from a Stacheldraht CLIENT --TO--> SERVER. The ICMP reply
will not have an associated ICMP echo request packet. Other
associated signatures: Stacheldraht Server Reply, detects server
sending packets to client. Loki ICMP tunneling, which can also
detect Stacheldraht traffic. Large ICMP Traffic , detects a
reported bug in the Stacheldraht code that sends out large
>1000 byte packets.
- 6505—Trinoo Client request
(severity 5, DoS): Trinoo clients communicate by default on UDP
port 27444 using a default command set. This signature looks for
UDP packets containing potential commands from a Trinoo CLIENT
>TO> SERVER.
- 6506—Trinoo Server reply (severity
5, DoS): Trinoo clients communicate by default on UDP port 27444
using a default command set. This signature looks for UDP packets
containing potential commands from a Trinoo CLIENT>TO>
SERVER.
- 6507—TFN2K DDoS Control traffic
(severity 5, DoS): TFN2K is a more robust and flexible version of
the original Tribe Flood Network. This signature identifies the
control traffic from the hackers client console and the server
(zombie) machine.
- 6508—mstream DDoS Control traffic
(severity 5, DoS): Mstream is a Unix based distributed DoS tool
similar to Trinoo, TFN and Stacheldraht. Mstream uses the Stream (stream.c)
DoS as its method of assault. This signature identifies the
control traffic between both the attacker <-> client (aka
handler), and between the client (aka handler) <-> server (aka
agent or daemon).
|
|