Alteon Application Switch Operating System Application Guide
Advanced Denial of Service Protection
608
Document
ID:
RDWR-ALOS-V2900_AG1302
FullXmasScan A TCP packet with all control bits
set.
Alteon checks for TCP packets with all of the
control bits set, and drops any matching
packets.
FinScan
A TCP packet with only the FIN bit
set.
Alteon checks for TCP packets with only the
FIN bit set, and drops any matching packets.
VecnaScan
A TCP packet with only the URG,
PUSH, URG|FIN, PSH|FIN, or
URG|PSH bits set.
Alteon checks for TCP packets with only the
URG, PUSH, URG|FIN, PSH|FIN, or URG|PSH
bits set and drops any matching packets.
Xmascan
Sequence number is zero and the
FIN, URG, and PSH bits are set.
Alteon checks for any TCP packets where the
sequence number is zero and the FIN, URG,
and PSH bits are set, and drops any
matching packets.
SYNFIN Scan
SYN and FIN bits set in the packet.
Alteon checks for TCP packets with the SYN
and FIN bits set, and drops any matching
packets.
FlagAbnormal A TCP packet with an abnormal
control bit combination set.
Alteon checks for an abnormal control bit
combination, and drops any matching
packets.
SynData
A TCP packet with the SYN bit set
and that also has a payload.
Alteon checks for TCP packets with the SYN
bit set and that also has a payload, and
drops any matching packets.
SynFrag
A TCP packet with the SYN and more
fragments bits set.
Alteon checks for TCP packets with the SYN
and more fragments bits set, and drops any
matching packets.
FTPPort
A TCP packet with a source port of
20, a destination port of less than
1024 and the SYN bit set.
Alteon checks for TCP packets with a source
port of 20, a destination port of less than
1024, and the SYN bit set, and drops any
matching packets.
DNSPort
A TCP packet with a source port of
53, a destination port of less than
1024 and the SYN bit set.
Alteon checks for TCP packets with a source
port of 53, a destination port of less than
1024, and the SYN bit set and drops any
matching packets.
SeqZero
A TCP packet with a sequence
number of zero.
Alteon checks for TCP packets with a
sequence number of zero, and drops any
matching packets.
AckZero
A TCP packet with an
acknowledgement number of zero
and the ACK bit set.
Alteon checks for TCP packets with an
acknowledgement number of zero and the
ACK bit set, and drops any matching packets.
TCPOptLen
A TCP packet with a TCP options
length of less than two or where the
TCP options length is greater than
the TCP header length.
Alteon checks for TCP packets with a TCP
options length of less than two or where the
TCP options length is greater than the TCP
header length, and drops any matching
packets.
UDPLen
An UDP packet with a UDP header
length of less than 8 bytes or where
the IP data length is less than the
UDP header length.
Alteon checks for UDP packets with a UDP
header length of less than 8 bytes or where
the IP data length is less than the UDP
header length, and drops any matching
packets.
Table 50: DoS Attacks Detected by Alteon
DoS Attack
Description
Action
Содержание Alteon
Страница 2: ...Alteon Application Switch Operating System Application Guide 2 Document ID RDWR ALOS V2900_AG1302 ...
Страница 42: ...Alteon Application Switch Operating System Application Guide Preface 42 Document ID RDWR ALOS V2900_AG1302 ...
Страница 582: ...Alteon Application Switch Operating System Application Guide High Availability 582 Document ID RDWR ALOS V2900_AG1302 ...