Cisco IOS Malicious IPV4 Packet Sequence Denial Of Service Vulnerability Signature

Jensenne Roculan <[email protected]> Fri, 18 Jul 2003 09:38:07 -0600 (MDT)
Newsgroups gmane.comp.security.aris
Message-ID <[email protected]>
Hi there,

The DeepSight Threat Analyst Team have created a series of Snort
signatures for the recently announced denial of service vulnerability in
Cisco IOS, as detailed in the following advisory:

http://www.cisco.com/warp/public/707/cisco-sa-20030717-blocked.shtml

It should be noted that these signatures may be inappropriate for networks
that see these uncommon IP protocol types for legitimate reasons on a
regular basis.

Signatures
----------
alert ip any any -> any any \
(msg:"Suspicious Traffic - IP Protocol 53 (SWIPE)"; \
ip_proto: 53; \
classtype:misc-activity; rev:1;)

alert ip any any -> any any \
(msg:"Suspicious Traffic - IP Protocol 55 (IP Mobility)"; \
ip_proto: 55; \
classtype:misc-activity; rev:1;)

alert ip any any -> any any \
(msg:"Suspicious Traffic - IP Protocol 77 (Sun ND)"; \
ip_proto: 77; \
classtype:misc-activity; rev:1;)

alert ip any any -> any any \
(msg:"Suspicious Traffic - IP Protocol 103 (PIM)"; \
ip_proto: 103; \
classtype:misc-activity; rev:1;)

False Positives
---------------
In the event that the aforementioned IP protocols are being used
legitimately within a network, these signatures will false positive on
such traffic. These signatures are most effective if deployed in an
environment that does not expect to see traffic containing any of these
uncommon IP protocols.


Jensenne Roculan
Symantec Corporation
http://www.symantec.com
(403) 261-5431