Skip to main content
Version: v6

Pattern Score


Overview

In today’s networks, cyber-attacks cause damage or theft and disrupt services with enormous economic and financial impacts. Software implementations cannot meet performance goals; a combination of software and hardware can be more effective for high-performance pattern matching. Packet content scanning at high speed has become extremely important due to its applications in network security, network monitoring, and traffic management in general.

Haltdos supports pattern scoring on the behalf of the behavior of the packet.

How to Use:

  1. Stack > Resource > DDoS > Advance Settings > Pattern Score

  2. Conifgure the settings.

  3. Click on Save Changes.

ParameterAccepted ValuesDescription
TCP SYN PACKET WITH NO OPTIONSLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
OUT OF RANGE MSSLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
MSS IN NON-SYN PACKETLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
WINDOW SCALE IN NON-SYN PACKETLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
TOP SOURCE PORT TOP TALKERLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
SOURCE PORT ZEROLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
SOURCE PORT OUT OF RANGELOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
TCP SEQUENCE NUMBER TOP TALKERLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
TCP SEQUENCE NUMBER ZEROLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
TCP URGENT POINTER WITHOUT FLAGLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
TCP ACK NUMBER WITHOUT FLAGLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
TCP FLAGS TOP TALKERLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
SUSPICIOUS TCP FLAG COMBINATIONSLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
TCP RESERVED FLAGSLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
TCP SUSPICIOUS WINDOW SIZELOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
SOURCE PREFIX TOP TALKERLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
SUSPICIOUS CHECKSUMLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
TCP URGENT POINTER TOP TALKERLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
ICMP DESTINATION TOP TALKERLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
UDP DESTINATION TOP TALKERLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS DESTINATION TOP TALKERLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS ANY QUERYLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS BAD ANSWER COUNTLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS BAD EDNS0 NAMELOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS BAD FLAGSLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS BAD LENGTHLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS BAD NAMESERVER COUNTLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS BAD RETURN CODELOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS EDNS0 WITH DOLOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH
DNS RARE QUERY TYPELOW, MEDIUM, HIGHSpecify suspicion score as LOW, MEDIUM or HIGH