
99
Table: Hacker attack types recognized by the IDS
Intrusion Name
Detect Parameter
Blacklist Type of Block
Duration
Drop Packet Show Log
Ascend Kill
Ascend Kill data
Src IP
DoS
Yes
Yes
WinNuke
TCP
Port 135, 137~139,
Flag: URG
Src IP
DoS
Yes
Yes
Smurf
ICMP type 8
Des IP is broadcast
Dst IP
Victim
Protection
Yes
Yes
Land attack
SrcIP = DstIP
Yes
Yes
Echo/CharGen
Scan
UDP Echo Port and
CharGen Port
Yes
Yes
Echo Scan
UDP Dst Port =
Echo(7)
Src IP
Scan
Yes
Yes
CharGen Scan
UDP Dst Port =
CharGen(19)
Src IP
Scan
Yes
Yes
X’mas Tree Scan
TCP Flag: X’mas
Src IP
Scan
Yes
Yes
IMAP
SYN/FIN Scan
TCP Flag: SYN/FIN
DstPort: IMAP(143)
SrcPort: 0 or 65535
Src IP
Scan
Yes
Yes
SYN/FIN/RST/ACK
Scan
TCP
No Existing session
And Scan Hosts more
than five.
Src IP
Scan
Yes
Yes
Net Bus Scan
TCP
No Existing session
DstPort = Net Bus
12345,12346, 3456
SrcIP
Scan
Yes
Yes
Back Orifice Scan
UDP, DstPort = Orifice
Port (31337)
SrcIP
Scan
Yes
Yes
SYN Flood
Max TCP Open
Handshaking Count
(Default 100 c/sec)
Yes
ICMP Flood
Max ICMP Count
(Default 100 c/sec)
Yes
ICMP Echo
Max PING Count
(Default 15 c/sec)
Yes
Summary of Contents for BiPAC 8500
Page 4: ...Chapter 5 Troubleshooting 172 Appendix Product Support Contact 173...
Page 33: ...Status 8500 29...
Page 34: ...8520 30...
Page 35: ...8501 31...
Page 36: ...8501 R2 32...
Page 37: ...8521 33...
Page 86: ...EFMBond 4 wired Connection 82...
Page 104: ...Src IP Source IP Src Port Source Port Dst Port Destination Port Dst IP Destination IP 100...
Page 126: ...Example Configuring a IPSec Host to LAN VPN Connection 122...