VoIPMaster 260W

Intrusion Name Detect Parameter Blacklist Type of Block Drop Packet Duration

Show Log

Ascend Kill

WinNuke

Smurf

Land attack

Echo/CharGen Scan

Echo Scan

CharGen Scan

X’mas Tree Scan

IMAP

SYN/FIN Scan

SYN/FIN/RST/ACK

Scan

Net Bus Scan

Back Orifice Scan

SYN Flood

ICMP Flood

ICMP Echo

Ascend Kill data

TCP

Port 135, 137~139,

Flag: URG

ICMP type 8

Des IP is broadcast

SrcIP = DstIP

UDP Echo Port and

CharGen Port

UDP Dst Port =

Echo(7)

UDP Dst Port =

CharGen(19)

TCP Flag: X’mas

TCP Flag: SYN/FIN

DstPort: IMAP(143)

SrcPort: 0 or 65535

TCP,

No Existing session

And Scan Hosts more than five.

TCP

No Existing session DstPort = Net Bus 12345,12346, 3456

UDP, DstPort =

Orifice Port (31337)

Max TCP Open

Handshaking Count

(Default 100 c/sec)

Max ICMP Count (Default 100 c/sec)

Max PING Count (Default 15 c/sec)

Src IP

DoS

Yes

 

 

 

Src IP

DoS

Yes

 

 

 

Dst IP

Victim

Yes

Protection

 

 

 

 

Yes

 

 

 

 

 

Yes

 

 

 

Src IP

Scan

Yes

 

 

 

Src IP

Scan

Yes

 

 

 

Src IP

Scan

Yes

Src IP

Scan

Yes

 

 

 

Src IP

Scan

Yes

 

 

 

SrcIP

Scan

Yes

 

 

 

SrcIP

Scan

Yes

 

 

 

 

 

 

 

 

 

 

 

 

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Src IP: Source IP

Src Port: Source Port

Dst Port: Destination Port

Dst IP: Destination IP

63