[Bro-Dev] [JIRA] (BIT-1314) Detect "quantum insert" type of attacks

yun (JIRA) jira at bro-tracker.atlassian.net
Wed Apr 29 04:00:02 PDT 2015

    [ https://bro-tracker.atlassian.net/browse/BIT-1314?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=20507#comment-20507 ] 

yun commented on BIT-1314:

A patch that fixes rexmit_inconsistency for QI can be found here: https://github.com/fox-it/quantuminsert/blob/master/detection/bro/rexmit_inconsistency-bro-2.3.2.patch

> Detect "quantum insert" type of attacks
> ---------------------------------------
>                 Key: BIT-1314
>                 URL: https://bro-tracker.atlassian.net/browse/BIT-1314
>             Project: Bro Issue Tracker
>          Issue Type: New Feature
>          Components: Bro
>            Reporter: David André
> Add detection for "quantum insert" type of attacks. Since the leaked information is classified, I will try to explain in unclassified form what it is about.
> The idea is that you have a passive adversary that sniff your TCP sequence numbers and inject its malicious payload faster than the real server.
> One of the leaked documents mentions as an alerting mechanism to detect duplicate TCP sequence numbers from same source, where at least 10% of the beginning of the content of the two packets differs.

This message was sent by Atlassian JIRA

More information about the bro-dev mailing list