Re: Spam sent from compromised (web)hosts vs botnet spam
Dan Oetting <[email protected]> Fri, 22 Mar 2013 06:13:21 -0600
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On Mar 22, 2013, at 5:13, Paul Smith <[email protected]> wrote: > If it was something with more 'payload' than ICMP (UDP, email, etc), it could possibly be extended to other types of abuse alert (port scans, login attacks, etc) The ICMP type 3 packet carries the first 64 bits of the data gram message it is responding to. For a TCP stream that is the source port, destination port and sequence number. Everything a netmom needs to find the offending packets and/or filter out false reports. I originally suggested using the ICMP for other types of abuse and dubbed it a SNARP for Simple Network Abuse Report Protocol. -- Dan Oetting - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org