Detecting DDoS/DoS on ASA w AIP-SSM

Unanswered Question
Dec 23rd, 2009
User Badges:


/* Style Definitions */ table.MsoNormalTable {mso-style-name:"Обычная таблица"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:""; mso-padding-alt:0cm 5.4pt 0cm 5.4pt; mso-para-margin:0cm; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; mso-ansi-language:#0400; mso-fareast-language:#0400; mso-bidi-language:#0400;}

Hello!

I'm battling with one problem - I need to detect and (attention) to produce an alert (say, an e-mail alert) after the detection of a DDoS attack - let's take TCP Syn Flood on a particular IP.

What I have: MARS and ASA/AIP-SSM which is controlled via Cisco Security Manager.


As far as I know, AIP-SSM does not support Normalizer signature (3050 for TCP SYN) so it will never fire an alert for this (but this could definitely solve my problem)  And ASA has basic threat-detection capabilities and it produces an ASA-4-733100 syslog event after detecting a threat.

But as far as I know I can't a) configure more sophisticated parameters of the ASA's threat-detection on CSM as it doesn't support this in it's interface (at least 3.3.1 version) b) MARS (6.0.4 in my case) also doesn't know anything about this feature (am I right?)

So I can either a) use a Flex-config on CSM to tune the threat-detection feature and write custom parser on MARS b) write custom rule on MARS to catch all the "Built TCP-connection" and "Teardown TCP .... with SYN" messages and to produce alert after hitting a threshold

But may be there is a more straightforward way to do this? Who can advise?

Regards, Amir

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
vlmacko Thu, 12/31/2009 - 01:35
User Badges:

Hi Amir,

did you try use "anomaly detection" feature on IPS module ?

I think, this can help to identify "attack" for your host  ..


Regards,

Vladimir

Amir Asfandyarov Tue, 01/05/2010 - 02:48
User Badges:

Hi,

Vladimir, thanks for your reply.

Yes, I've tried to use this but may be I've tuned it the wrong way - I am sure it will detec host/ports scans/sweeps but can it discover SYN or FIN floods (I mean, a lot of connections to one host with the same TCP-flag, for eg?  I didn't find anything near that.

May be I'm wrong?


Regards, Amir.

Actions

This Discussion

Related Content