<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Attackers showing inside subnets in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/attackers-showing-inside-subnets/m-p/2156633#M53860</link>
    <description>&lt;P&gt;All my attackers IP addresses are from my inside network. I never have an external IP show up as an attacker, its all internal. Then the victims are showing external IP addresses. Shouldn't it be the other way around, most of the time. &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:56:27 GMT</pubDate>
    <dc:creator>Matt Roberts</dc:creator>
    <dc:date>2019-03-10T12:56:27Z</dc:date>
    <item>
      <title>Attackers showing inside subnets</title>
      <link>https://community.cisco.com/t5/network-security/attackers-showing-inside-subnets/m-p/2156633#M53860</link>
      <description>&lt;P&gt;All my attackers IP addresses are from my inside network. I never have an external IP show up as an attacker, its all internal. Then the victims are showing external IP addresses. Shouldn't it be the other way around, most of the time. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/attackers-showing-inside-subnets/m-p/2156633#M53860</guid>
      <dc:creator>Matt Roberts</dc:creator>
      <dc:date>2019-03-10T12:56:27Z</dc:date>
    </item>
    <item>
      <title>Attackers showing inside subnets</title>
      <link>https://community.cisco.com/t5/network-security/attackers-showing-inside-subnets/m-p/2156634#M53861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will just explain by an example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say that you have "ICMP network scan" signature. A person in the internal vlan just launches an ICMP scan for some public IP addresses. Now since the ICMP scan was originated by the internal host and directed againt the external public IP, inside users will be termed as attackers and the targetted system as the victim.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just another question, what signatures are causing your internal users as the attackers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 18:14:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/attackers-showing-inside-subnets/m-p/2156634#M53861</guid>
      <dc:creator>Sonugnair_2</dc:creator>
      <dc:date>2013-04-30T18:14:13Z</dc:date>
    </item>
  </channel>
</rss>

