Rule Category

PROTOCOL-OTHER -- Snort alerted on traffic known to exploit vulnerabilities in protocols that do not fit into one of the other protocol rule categories.

Alert Message

PROTOCOL-OTHER Service Location Protocol denial-of-service attempt

Rule Explanation

This rule looks for a client sending a lot of messages to list available services to a server.

What To Look For

This rule alerts on a denial of service attempt against a server running Service Location Protocol (SLP).

Known Usage

Attacks/Scans seen in the wild

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

Rule Categories::Protocol::Other

MITRE::ATT&CK Framework::Enterprise::Impact::Endpoint Denial of Service::Application or System Exploitation

CVE

None

Rule Vulnerability

No information provided

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.

None