Technical Reference
OPEN824RL / RLW ADSL / VoIP Routers
68
The following table lists the
Intrusion Detection
fields and their definitions:
Field Definition
Intrusion Detection
If enabled, IDS will block Smurf attack attempts. The default is set to
Disabled.
Victim Protection Block
Duration
This is the duration for blocking
Smurf
attacks. The
default value is 600 seconds.
Scan Attack Block Duration
This is the duration for blocking hosts that attempt a
possible Scan attack. Scan attack types include
Xmas
scan, IMAP SYN/FIN scan
and similar attempts. The
default value 86400 seconds.
Block Duration
DoS Attack Block Duration
This is the duration for blocking hosts that attempt a
possible Denial of Service (DoS) attack. Possible DoS
attacks this attempts to block include
Ascend Kill
and
WinNuke.
Default value is 1800 seconds.
Max TCP Open Handshaking
Count
This is a threshold value to decide whether a
SYN Flood
attempt is occurring or not.
Default value is 100 TCP SYN per second.
Max PING Count
This is a threshold value to decide whether an
CIMP Echo Storm
is occurring or not.
Default value is 15 ICMP Echo Requests (PING) per second.
Max ICMP Count
This is a threshold to decide whether an
ICMP flood
is occurring or not. Default value
is 100 ICMP packets per second except ICMP Echo Requests (PING.) For
SYN Flood,
ICMP Echo Storm
and
ICMP Flood,
IDS will just warn the user in the Event Log. It
cannot protect against such attacks.
The following table lists hacker attack types:
Intrusion Name
Detect Parameter
Blacklist
Type of Block
Duration
Drop Packet
Show Log
Ascend Kill
Ascend Kill data
Src IP
DoS
Yes
Yes
WinNuke
TCP
Port 135, 137~139, Flag:
URG
Src IP
DoS
Yes
Yes
Smurf
ICMP type 8
Des IP is broadcast
Dst IP
Victim Protection
Yes
Yes
Land attack
SrcIP = DstIP
Yes
Yes
Echo/CharGen Scan
UDP Echo Port and
CharGen Port
Yes Yes
Echo Scan
UDP Dst Port = Echo(7) Src IP
Scan
Yes
Yes
CharGen Scan
UDP Dst Port =
CharGen(19)
Src IP
Scan
Yes
Yes
X’mas Tree Scan
TCP Flag: X’mas
Src IP
Scan
Yes
Yes
IMAP
SYN/FIN Scan
TCP Flag: SYN/FIN
DstPort: IMAP(143)
SrcPort: 0 or 65535
Src IP
Scan
Yes
Yes
SYN/FIN/RST/ACK Scan
TCP,
No Existing session And
Scan Hosts more than
five.
Src IP
Scan
Yes
Yes