Become a Beta Tester

DocsAttack Types

Abnormal Network Behaviour

Behaviour far outside normal that matches no specific signature.

A VM behaves far outside its own normal pattern but matches no known attack. Frabs compares each VM with its own history. By default it alerts your team rather than acting, because unusual is not always abuse.

Detectors (10)

DetectorMeasuresWarningIncidentCritical
Excessive Outbound ConnectionsDistinct destination addresses (addresses)1,000 in 1 h5,000 in 1 h10,000 in 1 h
Excessive New ConnectionsNew outbound connections per second (conn/s)500 in 30 s2,000 in 30 s5,000 in 30 s
Excessive Destination CountDistinct destination addresses (addresses)1,000 in 1 h5,000 in 1 h10,000 in 1 h
Excessive Port CountDistinct destination ports (ports)100 in 1 min500 in 5 min1,000 in 10 min
Excessive Packet RateOutbound packets per second (pkt/s)10,000 in 30 s50,000 in 30 s100,000 in 30 s
Excessive BandwidthOutbound megabits per second (Mbps)300 in 1 min600 in 30 s1,000 in 15 s
Connection BurstNew outbound connections per second (conn/s)1,000 in 10 s5,000 in 10 s10,000 in 10 s
Destination BurstDistinct destination addresses (addresses)500 in 1 min2,000 in 1 min5,000 in 1 min
Port BurstDistinct destination ports (ports)200 in 10 s1,000 in 10 s5,000 in 10 s
Persistent High-Rate TrafficOutbound packets per second (pkt/s)10,000 in 30 min50,000 in 30 min100,000 in 1 h

Change the thresholds

Use Custom Protection to change any of these, or set them for one VM. See Detectors and Thresholds.