<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syn flood DOS (6009) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syn-flood-dos-6009/m-p/573983#M92681</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default, flows with 200pkts/2sec above are alerted. You can change the threshold by CLI &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Aug 2006 17:47:29 GMT</pubDate>
    <dc:creator>aghaznavi</dc:creator>
    <dc:date>2006-08-14T17:47:29Z</dc:date>
    <item>
      <title>syn flood DOS (6009)</title>
      <link>https://community.cisco.com/t5/network-security/syn-flood-dos-6009/m-p/573982#M92680</link>
      <description>&lt;P&gt;The signature for syn flood DOS (6009) has two values that I can see will alter the signature threshold.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;event-counter&lt;/P&gt;&lt;P&gt;      -----------------------------------------------&lt;/P&gt;&lt;P&gt;         event-count: 2600 default: 200&lt;/P&gt;&lt;P&gt;         event-count-key: AxBx &amp;lt;defaulted&amp;gt;&lt;/P&gt;&lt;P&gt;         specify-alert-interval&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;            yes&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;               alert-interval: 2 default: 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The definition for the signature is that it will detect a flood of TCP SYN packets at a rate of 100 per second or greater. We have tried to adjust the signature that this value is higher and no matter what the event count is, it continues to trigger in our environment. At 1300 syns per/sec, (event-count: 2600) an alert is still received for http proxy servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have I over looked the parameter that needs to be adjusted in order to increase the threshold of this signature or is it just not tunable. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:09:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syn-flood-dos-6009/m-p/573982#M92680</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2019-03-10T10:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: syn flood DOS (6009)</title>
      <link>https://community.cisco.com/t5/network-security/syn-flood-dos-6009/m-p/573983#M92681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default, flows with 200pkts/2sec above are alerted. You can change the threshold by CLI &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2006 17:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syn-flood-dos-6009/m-p/573983#M92681</guid>
      <dc:creator>aghaznavi</dc:creator>
      <dc:date>2006-08-14T17:47:29Z</dc:date>
    </item>
  </channel>
</rss>

