SIGN:PROTOCOL-FLOOD

Protocol-based flood

Type ID

SIGN:PROTOCOL-FLOOD

Security profile

Alerts of this type are visible in the following security profiles:

  • MEDIUM
  • HIGH
  • PARANOID

Risk

The base risk for this alert is 7.

Cause

One or more hosts have sent a suspiciously high amount of packets with the same application layer (e.g., ping requests) to a single, target host.

Solution

Verify the device configuration and status, and the possible presence of malicious actors.

Product versions

Guardian 19.0.4

Trace

Alerts of this type are expected to generate traces.

Deduplication key

  • Attribute TYPE_ID
  • Attribute TRIGGER_ID
  • Attribute DESTINATION_NODE_ID
  • Attribute PROTOCOL