Actions
Documentation #6369
openstream: document stream.3whs_syn_flood and stream.3whs_synack_flood
Affected Versions:
Effort:
Difficulty:
Label:
Description
These events are not self explanatory, as they are not general scan detectors, but instead flag special cases of syn or syn/ack retransmissions within a flow.
Related commits:7bfee147ef6caefe0dd4444a088f451188108e0a
(#5856)4c6463f3784f533a07679589dab713096137a439
Updated by Victor Julien about 1 year ago
- Related to Bug #5856: stream: SYN/ACK timestamp checking blocks valid traffic added
Updated by Victor Julien about 1 year ago
Additionally, we need to consider how this behavior can be observed. There is the stream-event keyword and the anomaly record type, but neither of them will give details.
Updated by Juliana Fajardini Reichow 3 months ago
- Related to Documentation #7223: document 'stream-event' keyword added
Actions