DNP3: Non-DNP3 Traffic

This signature detects non-DNP3 traffic on the default port.

Extended Description

The existence of non DNP3 traffic on DNP3 ports is abnormal, and could indicate that a remote attacker is attempting to bypass firewall rules that allow DNP3 communication, cause denial of service conditions on devices that mishandle malformed packets, or tunnel traffic over DNP3 protocol and conduct further attacks. Non-DNP3 traffic arriving at DNP3 ports may also be the result of configuration or implementation errors.

Short Name
SCADA:DNP3:NON-DNP3
Severity
Info
Recommended
False
Recommended Action
None
Category
SCADA
Keywords
Non-DNP3 Traffic
Release Date
07/27/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/20000
False Positive
Rarely

Found a potential security threat?