SIGN:TCP-FLOOD

TCP flood

Type ID

SIGN:TCP-FLOOD

Security profile

Alerts of this type are visible in the following security profiles:

  • MEDIUM
  • HIGH
  • PARANOID

Risk

The base risk for this alert is 7.

Cause

One or more hosts have sent a great amount of anomalous TCP packets or TCP FIN packets to a single, target host.

Solution

Verify the device configuration and status, and the possible presence of malicious actors.

Product versions

Guardian 19.0.4

Trace

Alerts of this type are expected to generate traces.

Deduplication key

  • Attribute DESTINATION_NODE_ID
  • Attribute TYPE_ID
  • Attribute TRIGGER_ID