SIGN:TCP-FLOOD
TCP flood
Type ID
SIGN:TCP-FLOOD
Security profile
Alerts of this type are visible in the following security profiles:
- MEDIUM
- HIGH
- PARANOID
Risk
The base risk for this alert is 7.
Cause
One or more hosts have sent a great amount of anomalous TCP packets or TCP FIN packets to a single, target host.
Solution
Verify the device configuration and status, and the possible presence of malicious actors.
Product versions
Guardian 19.0.4
Trace
Alerts of this type are expected to generate traces.
Deduplication key
- Attribute
DESTINATION_NODE_ID - Attribute
TYPE_ID - Attribute
TRIGGER_ID