Rule: -- Sid: 111-7 -- Summary: This event is generated when the pre-processor stream4 detects network traffic that may constitute an attack. -- Impact: This may indicate scanning activity. -- Detailed Information: The pre-processor stream4 has detected network traffic that may indicate a scan is in progress. That is, packets with the SYN, ACK, URG and PUSH flags set have been detected. -- Affected Systems: All systems -- Attack Scenarios: An attacker may utilize scanning techniques to determine possible points of exploitation against a host. -- Ease of Attack: Simple. Many scanning tools exist. -- False Positives: None Known. -- False Negatives: None Known. -- Corrective Action: Check the target host for signs of compromise. Ensure the system is up to date with any appropriate vendor supplied patches. -- Contributors: Martin Roesch Sourcefire Vulnerability Research Team Nigel Houghton -- Additional References: --