12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IDS eventsSuspicious activity369DNS Malformed DataBase Event:Details:Response:Affected:DNS_INVALID_ADDRLENIn the additional record section of a DNS packet an IPv4 address was detected that was not 4 byteslong.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sDNS SpecificationsDNS Malformed DataBase Event:Details:Response:Affected:DNS_INVALID_TTLA TTL (Time To Live) value larger than the maximum legal value according to the RFC was detectedin a DNS packet.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sDNS SpecificationsDNS Malformed DataBase Event:Details:Response:Affected:DNS_DATA_AFTER_ENDExtra data was sent after a valid DNS packet. Probably an overflow attempt.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sDNS SpecificationsDNS Malformed DataBase Event:Details:Response:Affected:DNS_PACKET_OVERRUNExtra data was sent after a valid DNS packet. This represents a possible overflow attempt.If seen in sufficient volume or variation location and audit of client and server is recommended.Examination of the packet contents may provide some additional information about the particularcommand.No specific targets.False Positives: None known.<strong>Reference</strong>sDNS Specifications

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!