MS-RPC: Evasion Technique (5a)

This anomaly triggers when it detects packets containing known evasion techniques that affect the SMB, DCE, RPC, and MS RPC protocols. These packets are normally not seen in traffic and indicate attempts to evade network defense systems by sending invalid, out of order, or heavily fragmented communications. Use this anomaly only at WAN borders to reduce false positive possibilities.

Short Name
MS-RPC:EVASION:FRAG2-SMALL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
MS-RPC
Release Date
08/24/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?