Alteon Application Switch Operating System Application Guide
Advanced Denial of Service Protection
Document ID: RDWR-ALOS-V2900_AG1302
609
UDPPortZero
An UDP packet with a source or
destination port of zero.
Alteon checks for UDP packets with a source
or destination port of zero, and drops any
matching packets.
Fraggle
Similar to a smurf attack, attacks
are directed to a broadcast address,
except that the packets sent are
UDP, not ICMP.
Deny all the UDP packets with destination
address set to a broadcast address.
User action: Configure
Pepsi
An UDP packet with a source port of
19 and destination port of 7, or vice
versa.
Alteon checks for UDP packets with a source
port of 19 and destination port of 7, or vice
versa, and drops any matching packets.
RC8
An UDP packet with a source and
destination port of 7.
Alteon checks for UDP packets with a source
and destination port of 7, and drops any
matching packets.
SNMPNull
An UDP packet with a destination
port of 161 and no payload.
Alteon checks for UDP packets with a
destination port of 161 and no payload and
drops any matching packets.
ICMPLen
An ICMP packet with an improper
ICMP header length.
Alteon checks for ICMP packets with an
improper ICMP header length and drops any
matching packets.
Smurf
The attacker sends ICMP ping
requests to multiple broadcast
destination IP (x.x.x.255). The
packet contains spoofed source IP of
the victim.
Alteon checks every packet for destination IP
set to a broadcast address in a filter, and
drops any matching packet.
ICMPData
An ICMP packet with a zero
fragment offset and a large payload.
Alteon checks for ICMP packets with a zero
fragment offset and a large payload, and
drops any matching packets.
ICMPOff
An ICMP packet with a large
fragment offset.
Alteon checks for ICMP packets with a large
fragment offset, and drops any matching
packets.
ICMPType
An ICMP packet where the type is
unassigned or reserved.
Alteon checks for ICMP packets where the
type is unassigned or reserved, and drops
any matching packets.
IGMPLen
An IGMP packet with an improper
IGMP header length.
Alteon checks for IGMP packets with an
improper IGMP header length, and drops any
matching packets.
IGMPFrag
An IGMP packet with the more
fragments bit set and a non-zero
fragment offset.
Alteon checks for IGMP packets with the
more fragments bit set and a non-zero
fragment offset, and drops any matching
packets.
IGMPType
An IGMP packet with the type of
unassigned or reserved.
Alteon checks for IGMP packets with the type
of unassigned or reserved, and drops any
matching packets.
ARPLen
An ARP request or reply packet with
an improper length.
Alteon checks for ARP request or reply
packets with an improper length, and drops
any matching packets.
ARPNBCast
An ARP request packet with a non-
broadcast destination MAC address.
Alteon checks for ARP request packets with a
non-broadcast destination MAC address, and
drops any matching packets.
Table 50: DoS Attacks Detected by Alteon
DoS Attack
Description
Action