91
Victim Protection
Block Duration This is the duration for blockin
g
Smurf attacks. Default value is
600 seconds.
Scan Attach Block
Duration
This is the duration for blockin
g
hosts that attempt a possible
Scan attack. Scan attack types include X’mas scan, IMAP
SYN/FIN scan and similar attempts. Default value is 86400
seconds.
DOS Attack Block
Duration
This is the duration for blockin
g
hosts that attempt a possible
Denial of Service (DoS) attack. Possible DoS attacks this
attempts to block include Ascend Kill and WinNuke. Default
value is 1800 seconds.
Maximum TCP
Open Handshakin
g
Count
This is a threshold value to decide whether a SYN Flood
attempt is occurrin
g
or not. Default value is 100 TCP SYN per
seconds
Maximum Pin
g
Count
This is a threshold value to decide whether an ICMP Echo
Storm is occurrin
g
or not. Default value is 15 ICMP Echo
Requests (PING) per second.
Maximum ICMP
Count
This is a threshold to decide whether an ICMP flood is occurrin
g
or not. Default value is 100 ICMP packets per seconds except
ICMP Echo Requests (PING).
For SYN Flood, ICMP Echo Storm and ICMP flood, IDS will just warn the user in the
Event Log. It cannot protect against such attacks.
Intrusion Name Detect
Parameter Blacklist
T
ype of
Block
Duration
Drop
Packet Show
Log
Ascend Kill Ascend Kill data Src IP DoS Yes Yes
WinNuke
TCP
Port 135,
137~139, Fla
g
:
URG
Src IP DoS Yes Yes