Documentation #6369
open
stream: document stream.3whs_syn_flood and stream.3whs_synack_flood
Added by Victor Julien almost 2 years ago.
Updated about 1 month ago.
Description
These events are not self explanatory, as they are not general scan detectors, but instead flag special cases of syn or syn/ack retransmissions within a flow.
Related commits:
7bfee147ef6caefe0dd4444a088f451188108e0a
(#5856)
4c6463f3784f533a07679589dab713096137a439
- Description updated (diff)
- Related to Bug #5856: stream: SYN/ACK timestamp checking blocks valid traffic added
Additionally, we need to consider how this behavior can be observed. There is the stream-event keyword and the anomaly record type, but neither of them will give details.
- Target version changed from 8.0.0-beta1 to 8.0.0-rc1
- Target version changed from 8.0.0-rc1 to 8.0.0
- Status changed from New to Assigned
- Assignee changed from OISF Dev to Victor Julien
- Target version changed from 8.0.0 to 9.0.0-beta1
Also available in: Atom
PDF