Snort mailing list archives

Re: Very high amount of "TCP Small Segment Threshold Exceeded"


From: waldo kitty <wkitty42 () windstream net>
Date: Tue, 28 Feb 2012 14:52:39 -0500

On 2/27/2012 03:39, Giacomo wrote:
Hi there,

I recently started using Snort. After enabling the (default) preprocessor configuration I started receiving very 
large amounts of events regarding stream5.
Since it is a server that is not being used for anything I assume this event is generated by my SSH connection. A 
couple of topics have discussed this but none come with a very clear answer why this is occurring and how you can 
solve it.
The only two suggestions I found was to change the max_tcp value in stream5_global or increase the memcap. But both 
of these suggestions don't work. So I am wondering if any one of you has an idea why this is occurring and what I can 
do about it.

what, exactly, are the SIDs being reported? the items you saw are for one or two 
things but stream5 can alert on numerous items...

here's what the snort-2.9.2.1's README.stream5 has to say...

Alerts
======
Stream5 uses generator ID 129. It is capable of alerting on 10 anomalies, all of 
which relate to TCP anomalies. There are no anomaly detection capabilities for 
UDP or ICMP.

SID   Description
---   -----------
1     SYN on established session
2     Data on SYN packet
3     Data sent on stream not accepting data
4     TCP Timestamp is outside of PAWS window
5     Bad segment, overlap adjusted size less than/equal 0
6     Window size (after scaling) larger than policy allows
7     Limit on number of overlapping TCP packets reached
8     Data after Reset packet
9     Possible Hijacked Client
10    Possible Hijacked Server
11    TCP packet with any control flags set
12    Limit on number of consecutive small segments reached
13    4-way handshake detected
14    Packet missing timestamp


[ yes, there's a typo up there where it says 10 anomalies and then shows 14 of 
them ;) ]

------------------------------------------------------------------------------
Keep Your Developer Skills Current with LearnDevNow!
The most comprehensive online learning library for Microsoft developers
is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
Metro Style Apps, more. Free future releases when you subscribe now!
http://p.sf.net/sfu/learndevnow-d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: