<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP SYS Host Sweep in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-sys-host-sweep/m-p/545230#M98358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any ideas before the weekend?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 04 Aug 2006 14:55:16 GMT</pubDate>
    <dc:creator>DFiore</dc:creator>
    <dc:date>2006-08-04T14:55:16Z</dc:date>
    <item>
      <title>TCP SYS Host Sweep</title>
      <link>https://community.cisco.com/t5/network-security/tcp-sys-host-sweep/m-p/545229#M98356</link>
      <description>&lt;P&gt;Seems like whenever a mail server connects and does a mass mailing to customers I see this sig fire.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also see the sig fire when "certain" users surf to websites with tracking cookies (DoubleClick, Akamai, etc.)  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the Sig DB at MySDN, this sig is benign as long as the traffic seen is internal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this the case?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-sys-host-sweep/m-p/545229#M98356</guid>
      <dc:creator>DFiore</dc:creator>
      <dc:date>2019-03-10T10:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYS Host Sweep</title>
      <link>https://community.cisco.com/t5/network-security/tcp-sys-host-sweep/m-p/545230#M98358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any ideas before the weekend?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Aug 2006 14:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-sys-host-sweep/m-p/545230#M98358</guid>
      <dc:creator>DFiore</dc:creator>
      <dc:date>2006-08-04T14:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYS Host Sweep</title>
      <link>https://community.cisco.com/t5/network-security/tcp-sys-host-sweep/m-p/545231#M98359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you mean TCP SYN Host sweep (3030-0)? I never really found it to be a useful signature, mostly because it doesn't report the port(s) being scanned. It is prone to false positives as well since it will fire on return traffic (like to an HTTP proxy for example).  Filtering can fix that if you're so inclined.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see these threads:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.1ddabf56" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.1ddabf56&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB?cmd=pass_through&amp;amp;location=outline" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;CommCmd=MB?cmd=pass_through&amp;amp;location=outline&lt;/A&gt;@^1@@.1dd99469&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Aug 2006 15:13:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-sys-host-sweep/m-p/545231#M98359</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-08-04T15:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: TCP SYS Host Sweep</title>
      <link>https://community.cisco.com/t5/network-security/tcp-sys-host-sweep/m-p/545232#M98360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll look at the threads and consider filtering out the fires I can explain (proxy server, email, etc.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a  good weekend...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Aug 2006 17:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-sys-host-sweep/m-p/545232#M98360</guid>
      <dc:creator>DFiore</dc:creator>
      <dc:date>2006-08-04T17:41:19Z</dc:date>
    </item>
  </channel>
</rss>

