PROLiNK Hurricane 9300G User Manual page 73

(802.11g) adsl2+ modem router
Hide thumbs Also See for Hurricane 9300G:
Table of Contents

Advertisement

Max ICMP Count: This is a threshold to decide whether an ICMP flood is occurring or not. Default
value is 100 ICMP packets per seconds except ICMP Echo Requests (PING).
For SYN Flood, ICMP Echo Storm and ICMP flood, IDS will just warn the user in the Event Log. It
cannot protect against such attacks.
Intrusion Name
Ascend Kill
WinNuke
Smurf
Land attack
Echo/CharGen Scan
Echo Scan
CharGen Scan
X'mas Tree Scan
IMAP
SYN/FIN Scan
SYN/FIN/RST/ACK
Scan
Net Bus Scan
Back Orifice Scan
SYN Flood
ICMP Flood
ICMP Echo
Src IP: Source IP
Dst Port: Destination Port
Chapter 4: Configuration
Table 2: Hacker attack types recognized by the IDS
Detect Parameter Blacklist
Ascend Kill data
Src IP
TCP
Port 135, 137~139,
Src IP
Flag: URG
ICMP type 8
Dst IP
Des IP is broadcast
SrcIP = DstIP
UDP Echo Port and
CharGen Port
UDP Dst Port =
Src IP
Echo(7)
UDP Dst Port =
Src IP
CharGen(19)
TCP Flag: X'mas
Src IP
TCP Flag: SYN/FIN
DstPort: IMAP(143)
Src IP
SrcPort: 0 or 65535
TCP,
No Existing session
Src IP
And Scan Hosts
more than five.
TCP
No Existing session
SrcIP
DstPort = Net Bus
12345,12346, 3456
UDP, DstPort =
SrcIP
Orifice Port (31337)
Max TCP Open
Handshaking Count
(Default 100 c/sec)
Max ICMP Count
(Default 100 c/sec)
Max PING Count
(Default 15 c/sec)
Src Port: Source Port
Dst IP: Destination IP
Hurricane 9300G (802.11g) ADSL2+ Modem Router
Type of Block
Drop Packet
Duration
DoS
Yes
DoS
Yes
Victim
Yes
Protection
Yes
Yes
Scan
Yes
Scan
Yes
Scan
Yes
Scan
Yes
Scan
Yes
Scan
Yes
Scan
Yes
Show Log
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
69

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents