Next: sfPortscan
Up: Stream5
Previous: Example Configurations
Contents
Stream5 uses generator ID 129. It is capable of alerting on 8 (eight)
anomalies, all of which relate to TCP anomalies. There are no
anomalies detected relating to UDP or ICMP.
The list of SIDs is as follows:
- SYN on established session
- Data on SYN packet
- Data sent on stream not accepting data
- TCP Timestamp is outside of PAWS window
- Bad segment, overlap adjusted size less than/equal 0
- Window size (after scaling) larger than policy allows
- Limit on number of overlapping TCP packets reached
- Data after Reset packet
Steven Sturges
2008-04-01
|