Livoa LogoLivoa
Snort Traffic Comparison
Parameter
Normal Network Traffic
Malicious Traffic (Detected by Snort)
Traffic Pattern
Regular, predictable communication between hosts
Rapid, repetitive connection attempts to multiple ports
Connection Rate
Low to moderate
Very high within a short time
Port Access
Access to specific service ports (80, 22, 443)
Sequential or random scanning of many ports
TCP Flags
Normal TCP handshake (SYN → SYN-ACK → ACK)
Excessive SYN packets without completing handshake
Packet Timing
Spread over time
Burst traffic in milliseconds
Source IP Behavior
Communicates with limited destination ports
Same source IP targets many ports
Snort Alert Status
❌ No alert generated
✅ Alert triggered
Alert Message
None
“TCP SYN Scan Detected”, “Possible Port Scan”
Priority Level
N/A
Priority: 0 (Suspicious / Malicious)
Example Tool
Browser, SSH client
Nmap, Masscan
Security Risk
Legitimate usage
Reconnaissance phase of an attack
TCP SYN Scan
Possible Port Scan

chart

by dimple

0
0 uses