Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Network Security: Firewall, NAT, QoS, IPS and more

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 04-07-2004, 04:51 PM
martindw's Avatar
Senior Member
 
Join Date: May 2002
Location: San Jose, CA
Posts: 191
Default Undetected portscan

Can anyone tell me why the following was not detected as a portscan? I happened to be looking at the packet filter livelog and saw it, but it never showed up in my portscan log.

The IP address 209.233.190.166 is a second IP address for my WAN port, masqued to an internal webserver (SSL only).

<font color="green"> 2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7149 DF PROTO=TCP SPT=3869 DPT=1025 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7150 DF PROTO=TCP SPT=3881 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7155 DF PROTO=TCP SPT=3882 DPT=3127 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7156 DF PROTO=TCP SPT=3883 DPT=6129 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:15 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7157 DF PROTO=TCP SPT=3884 DPT=139 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7722 DF PROTO=TCP SPT=3862 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7723 DF PROTO=TCP SPT=3869 DPT=1025 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7724 DF PROTO=TCP SPT=3881 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7747 DF PROTO=TCP SPT=3882 DPT=3127 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:18 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=7749 DF PROTO=TCP SPT=3883 DPT=6129 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9741 DF PROTO=TCP SPT=3881 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9742 DF PROTO=TCP SPT=3869 DPT=1025 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9743 DF PROTO=TCP SPT=3862 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9758 DF PROTO=TCP SPT=3884 DPT=139 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9759 DF PROTO=TCP SPT=3883 DPT=6129 WINDOW=64800 RES=0x00 SYN URGP=0
2004-Apr 7 09:45:24 (none) kernel: TCP Drop: IN=eth1 OUT= MAC=00:a0:cc:db:90:12:00:06:d7:ee:21:ae:08:00 SRC=209.233.197.111 DST=209.233.190.166 LEN=48 TOS=0x00 PREC=0x00 TTL=123 ID=9760 DF PROTO=TCP SPT=3882 DPT=3127 WINDOW=64800 RES=0x00 SYN URGP=0
</font>

TIA,

Dan
Reply With Quote
  #2 (permalink)  
Old 04-07-2004, 07:09 PM
Wizard
 
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 2,885
Default Re: Undetected portscan

do you have an IPS license?
Reply With Quote
  #3 (permalink)  
Old 04-07-2004, 08:43 PM
martindw's Avatar
Senior Member
 
Join Date: May 2002
Location: San Jose, CA
Posts: 191
Default Re: Undetected portscan

No, but IPSec isn't part of this. I have the professional version (up to 50 IPs) ASL license on this machine.
Reply With Quote
  #4 (permalink)  
Old 04-07-2004, 09:46 PM
Wizard
 
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 2,885
Default Re: Undetected portscan

well the portscanner function is wrapped into the ids/ips section of ASL5 which is enabled(as of right now) only by purchasing a seaprate ips/ids license.
Reply With Quote
  #5 (permalink)  
Old 04-08-2004, 11:47 PM
martindw's Avatar
Senior Member
 
Join Date: May 2002
Location: San Jose, CA
Posts: 191
Default Re: Undetected portscan

That's interesting. I'm on ASL 4, not 5, and in both versions 3 & 4 portscan detection <font color="red"> WAS </font> part of the basic license. . .the ips/ids license is something I've never heard of. Can you point me to some documentation?
Reply With Quote
  #6 (permalink)  
Old 04-09-2004, 12:19 AM
Wizard
 
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 2,885
Default Re: Undetected portscan

[ QUOTE ]
That's interesting. I'm on ASL 4, not 5, and in both versions 3 & 4 portscan detection <font color="red"> WAS </font> part of the basic license. . .the ips/ids license is something I've never heard of. Can you point me to some documentation?

[/ QUOTE ]
goto astaro.com and read the press release about v5.. As far as the portscanner not working in your v4 i have no idea on that one..
Reply With Quote
  #7 (permalink)  
Old 04-10-2004, 11:14 PM
JCB JCB is offline
Junior Member
 
Join Date: Apr 2004
Location: Auckland - New Zealand
Posts: 12
Default Re: Undetected portscan

It is disapointing to see that Portscan has been removed in ASL5. Intrusion detection is certainly a major feature, even for slaves "home users" who contributed so much in debugging and PROMOTING this product. I have sold so many ASL to clients that this is not funny..
I believe that if the original marketing idea was great, this is now turning unfair and frustrating. [img]/images/graemlins/confused.gif[/img]
Reply With Quote
  #8 (permalink)  
Old 04-12-2004, 05:06 PM
martindw's Avatar
Senior Member
 
Join Date: May 2002
Location: San Jose, CA
Posts: 191
Default Re: Undetected portscan

Just a follow-up bit of information; I would guess that the portscan I included above got overlooked because it was spaced out over time. . .5 ports scanned, 3-second pause, 5 more scanned, another 3-second pause, and then 6 more scanned. It would appear that the threshold for portscan detection in ASL doesn't include logic to detect scans that are done in this more leisurely manner.

By contrast, I scanned myself using the website at grc.com and got the PSD warning right away.

Either this, or the PSD doesn't work on secondary IP addresses on the same NIC; and since I can't get GRC to scan my alternate IP (and I don't have another portscanner) I can't prove with any certainty which of these two scenarios is correct. . .but I bet Astaro can. A little help, guys???

D
Reply With Quote
  #9 (permalink)  
Old 04-13-2004, 03:50 AM
Moderator
 
Join Date: Jul 2001
Location: southern California
Posts: 5,359
Default Re: Undetected portscan

Astaro 3.x doesn't seem to pickup a lot of scans I see...
We have Astaro protecting a Class C, and with Snort/ACID, I see a lot of scans for open SOCKS and Squid proxy servers, scanning 1 or 2 ports on each IP across our network.

Astaro's scanner seems to only detect multi-port scans.

You could d/l the source of the old PSD module from Astaro before, but I'm not sure where it is now.

Also, the 4.x PlusPack includes the kernel source.

Barry
Reply With Quote
  #10 (permalink)  
Old 04-13-2004, 04:02 AM
Wizard
 
Join Date: Jun 2003
Location: geocenter
Posts: 623
Default Re: Undetected portscan

Dan,

I think the scan wasn't fast enough to be detected:

<font class="small">Code:</font><hr /><pre>psd weight-threshold: 21 delay-threshold: 300 lo-ports-weight: 3 hi-ports-weight: 1</pre><hr />

If I am reading the rule for portscan detection right - this means ports below 1024 get a score of 3 and ports above 1. If the total score reaches 21 PSD would detect a scan but not if there are more than 300ms in between the single scan attempts.

There is a gap for exampbe between 09:45:15 and 09:45:18

Start calculating :-)

Greetings
cyclops
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:08 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.