Pre-defined sensitivity levels for portscan detection

When configuring detection settings, you select from these pre-defined sensitivity levels. Except for custom, each level has pre-set values for each protocol for the number of ports (TCP, UDP), protocols (IP), or hosts (TCP, UDP, IP, ICMP) that must be scanned within a set time interval (expressed in seconds). Also, all types of scans and sweeps are enabled.

Note

When counting ports or protocols, threat detection increments the number if the port or protocol in the current packet differs from the previous packet. For example, if you have an application that opens connections in 10 set ports randomly, the total number of ports scanned could mount so quickly that your port number will be exceeded within the interval. The system does not count only unique ports.

Exceeding the number within the interval can indicate a scanning attack. Portscan events are generated only when the port/protocol/host numbers are exceeded for the moving time interval window.

These sensitivity levels determine portscan detection behavior:

  • Low—This level uses the shortest time window for portscan detection, coupled with high counts for ports, protocols, and hosts. Thus, you should see portscan events for the most aggressive scanners only. Select this sensitivity level to suppress false positives, but remember that some types of port scans, such as slow or filtered scans, might be missed. For more detail on how low sensitivity detection works, see Detection in the low sensitivity level.

  • Medium—This level uses moderate values for both the interval and port/protocol/host counts. However, very active hosts such as network address translators and proxies might generate false positives. Add such hosts to the ignore scanner list. This is the default sensitivity level and a good place to start.

  • High—This level uses a much longer time window for portscan detection, coupled with lower counts for ports, protocols, and hosts. With this level, you are most likely to see events for even the least aggressive port scans or sweeps, so you are more likely to notice all attackers. However, this level would likely result in the most portscan events issued, and potentially the highest number of false positives.

  • Custom—If you want to configure any setting differently than one of the predefined sensitivity levels, or disable a particular type of scan or sweep, the level automatically switches to custom. If you want to adjust the options, first select the level that most closely matches what you want, then edit the values as appropriate.

Sensitivity level settings

Setting

Low

Medium

High

Interval (TCP/UDP/IP/ICMP)

60 seconds

90 seconds

600 seconds (10 minutes)

TCP/UDP portscan - Number of Ports

120 seconds

90 seconds

60 seconds

TCP/UDP portsweep - Number of Hosts

180 seconds

150 seconds

100 seconds

IP protocol scan - Number of Protocols

30 seconds

15 seconds

10 seconds

IP protocol sweep - Number of Hosts

25 seconds

20 seconds

10 seconds

ICMP host sweep - Number of Hosts

50 seconds

30 seconds

20 seconds