Rule: -- Sid: 111-4 -- Summary: This event is generated when the pre-processor stream4 detects network traffic that may constitute an attack. -- Impact: Unknown. -- Detailed Information: The pre-processor stream4 has detected network traffic that indicates data has been found outside the expected window for the data in a session. This is not normal network behavior and may indicate spurious activity or a malfunctioning operating system network stack. -- Affected Systems: All systems -- Attack Scenarios: -- Ease of Attack: Simple. Many automated packet generation tools exist. -- False Positives: None Known. -- False Negatives: None Known. -- Corrective Action: Check the target host for signs of compromise. Ensure the system is up to date with any appropriate vendor supplied patches. -- Contributors: Martin Roesch Sourcefire Vulnerability Research Team Nigel Houghton -- Additional References: --