Snort - the de facto standard for intrusion detection/prevention
next up previous contents
Next: sfPortscan Up: Stream5 Previous: Example Configurations   Contents

Alerts

Stream5 uses generator ID 129. It is capable of alerting on 8 (eight) anomalies, all of which relate to TCP anomalies. There are no anomalies detected relating to UDP or ICMP.

The list of SIDs is as follows:

  1. SYN on established session
  2. Data on SYN packet
  3. Data sent on stream not accepting data
  4. TCP Timestamp is outside of PAWS window
  5. Bad segment, overlap adjusted size less than/equal 0
  6. Window size (after scaling) larger than policy allows
  7. Limit on number of overlapping TCP packets reached
  8. Data after Reset packet



Steven Sturges 2008-04-01