Re: Spam sent from compromised (web)hosts vs botnet spam

Dan Oetting <[email protected]> Fri, 22 Mar 2013 06:13:21 -0600
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Mar 22, 2013, at 5:13, Paul Smith <[email protected]> wrote:

> If it was something with more 'payload' than ICMP (UDP, email, etc), it could possibly be extended to other types of abuse alert (port scans, login attacks, etc)

The ICMP type 3 packet carries the first 64 bits of the data gram message it is responding to. For a TCP stream that is the source port, destination port and sequence number. Everything a netmom needs to find the offending packets and/or filter out false reports.

I originally suggested using the ICMP for other types of abuse and dubbed it a SNARP for Simple Network Abuse Report Protocol.

-- Dan Oetting

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org