How to do it

The traffic patterns you should look for are:

  • ACK scanning: Multiple ACKs are sent usually to multiple ports in order to break the existing TCP connections
Figure 19.15: TCP ACK scanning
  • Unusual flag combinations: This refers to anything with a URG flag, FIN and RST, SYN-FIN, and so on. Unusual flag combinations are not the usual SYN, FIN or RST, with or without ACK. In the following screenshot, you see an example of this scenario. The operations FIN/PSH/URG are together called Xmas scan.
Figure 19.16: TCP unusual flag combinations

TCP scans with all flags set to zero. This scan is called null scan.

Figure 19.17: TCP null scan
  • Massive FIN-ACK scanning: Large number of packets with FIN and ACK flags set to one are sent to multiple ports in order to cause them to be closed or just to flood the network
Figure 19.18: TCP FIN-ACK scan
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.227.161.132