How to do it

The traffic patterns you should look for are:

  • ACK scanning: Multiple ACKs are sent usually to multiple ports in order to break the existing TCP connections
Figure 19.15: TCP ACK scanning
  • Unusual flag combinations: This refers to anything with a URG flag, FIN and RST, SYN-FIN, and so on. Unusual flag combinations are not the usual SYN, FIN or RST, with or without ACK. In the following screenshot, you see an example of this scenario. The operations FIN/PSH/URG are together called Xmas scan.
Figure 19.16: TCP unusual flag combinations ...

Get Network Analysis Using Wireshark 2 Cookbook - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.