- Use Case Reference : SUC009
- Use Case Title : Activities on source port 500 destination port 500/UDP
- Use Case Detection : Firewall / IDS
- Attacker Class : Opportunists / Targeting Opportunists / Professional
- Attack Sophistication : Unsophisticated / Low / Mid-High
- Identified tool(s) : Possible ike-scan
- Source IP(s) : Random
- Source Countries : Random
- Source Port(s) : 500/UDP
- Destination Port(s) : 500/UDP
Possible(s) correlation(s) :
- This UDP destination port is related to IKE isakmp. Often detected as an DoS attempt on Win2000.
- ike-scan
Sources :