ICMP flood attack

ICMP flood attack is one of the common DoS attacks, where a malicious user within the network will trigger a swarm of ICMP packets to a target host (such as a server):

Wireshark statistics can be used to identify whether there is any ICMP attack. The statistics can be viewed through Statistics | Protocol Hierarchy in the Wireshark header field. As shown in the preceding screenshot, there are 60,000 ICMP packets in a few seconds.

Get Network Analysis Using Wireshark 2 Cookbook - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.