Snort.TCP.SACK.Option.DoS

description-logoDescription

This signature indicates detection of a TCP protocol anomaly of which a TCP packet containing a SACK option has a unusual short length.

affected-products-logoAffected Products

Any host running TCP services

Impact logoImpact

Protocol Anomaly: This is an anomaly which may also indicate attack attempts in some cases.

recomended-action-logoRecommended Actions

This indicates detection of traffic that does not comply with the protocol standard.
Monitor the traffic from that network for any suspicious activity.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)