TCP: S2C Ambiguity Mismatching Overlapping Data

This protocol anomaly triggers when it detects a TCP segment retransmission from the server to client in which the retransmitted data differs from the original data. Because this is an extremely common IDS evasion attack, it is recommended to drop these packets.

Extended Description

Such a anomalous situation could indicate a TCP configuration or implementation error. It also could indicate that an attack against a TCP implementation is underway.

Short Name
TCP:S2C:AMBIG:OLAP-MISMATCH
Severity
Critical
Recommended
True
Recommended Action
Drop Packet
Category
TCP
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?