PaloAlto SCTP INIT Flood

Last updated on:

Applies to: Log360Log360 Cloud

About the rule

Rule Type

Standard

Rule Description

Detects flood attacks using SCTP INIT chunks with excessive session initiation attempts that can overwhelm systems.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "SCTP INIT Flood" select Action1.HOSTNAME,Action1.IDS_NAME,Action1.USERNAME,Action1.MESSAGE,Action1.THREAT_ID,Action1.DEST_IP,Action1.DEST_PORT,Action1.ACTION

Detection

Execution Mode

realtime

Log Sources

PaloAlto