📄 111-17.txt
字号:
Rule: --Sid: 111-17-- Summary: This event is generated when the pre-processor stream4detects network traffic that may constitute an attack.-- Impact: Unknown. This may be an IDS evasion attempt.--Detailed Information:The pre-processor stream4 has detected a TCP session that containsretransimitted data without the necessary retransmission request. Thismay be an attempt to evade any monitoring IDS.It may be possible for an attacker to send multiple small packets to ahost then disguise an actual attack in a retransmitted packet to thatsame host.--Affected Systems: All systems--Attack Scenarios: An attacker could cause a host to send multiple acknowledgement packetsthen supply one large malicious packet to the host disguised as aretransmission of data.-- Ease of Attack: Difficult.-- False Positives:None Known.--False Negatives:None Known.-- Corrective Action:Check the target host for signs of compromise.Ensure the system is up to date with any appropriate vendor supplied patches.--Contributors:Martin Roesch <roesch@sourcefire.com>Sourcefire Vulnerability Research TeamNigel Houghton <nigel.houghton@sourcefire.com>-- Additional References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -