Flood Detection; Figure 342 Smurf Attack - ZyXEL Communications Unified Security Gateway ZyWALL 1000 User Manual

Unified security gateway
Hide thumbs Also See for Unified Security Gateway ZyWALL 1000:
Table of Contents

Advertisement

Chapter 30 ADP
30.8.1.4 Filtered Port Scans
A filtered port scan may indicate that there were no network errors (ICMP unreachables or
TCP RSTs) or responses on closed ports have been suppressed. Active network devices, such
as NAT routers, may trigger these alerts if they send out many connection attempts within a
very small amount of time. These are some filtered port scan examples.
• TCP Filtered Portscan
• TCP Filtered Decoy
Portscan
• TCP Filtered
Portsweep
• ICMP Filtered
Portsweep
• IP Filtered
Distributed Portscan

30.8.2 Flood Detection

Flood attacks saturate a network with useless data, use up all available bandwidth, and
therefore make communications in the network impossible.
30.8.2.1 ICMP Flood Attack
An ICMP flood is broadcasting many pings or UDP packets so that so much data is sent to the
system, that it slows it down or locks it up.
30.8.2.2 Smurf
A smurf attacker (A) floods a router (B) with Internet Control Message Protocol (ICMP) echo
request packets (pings) with the destination IP address of each packet as the broadcast address
of the network. The router will broadcast the ICMP echo request packet to all hosts on the
network. If there are numerous hosts, this will create a large amount of ICMP echo request and
response traffic.
If an attacker (A) spoofs the source IP address of the ICMP echo request packet, the resulting
ICMP traffic will not only saturate the receiving network (B), but the network of the spoofed
source IP address (C).

Figure 342 Smurf Attack

452
• UDP Filtered Portscan
• UDP Filtered Decoy
Portscan
• UDP Filtered Portsweep
• TCP Filtered Distributed
Portscan
• IP Filtered Portscan
• IP Filtered Decoy
Portscan
• IP Filtered Portsweep
• UDP Filtered
Distributed Portscan
ZyWALL USG 1000 User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall usg 1000

Table of Contents