[ Contents] [ Prev] [ Next] [ Index] [ Report an Error]

Thwarting a FIN Scan

A FIN scan sends TCP segments with the FIN flag set in an attempt to provoke a response (a TCP segment with the RST flag set) and thereby discover an active host or an active port on a host. The use of TCP segments with the FIN flag set might evade detection and thereby help the attacker succeed in his or her reconnaissance efforts.

Before You Begin

For background information, read Understanding Attacker Evasion Techniques.

To thwart FIN scans, use the JUNOS CLI configuration editor to take either or both of the following actions.

[ Contents] [ Prev] [ Next] [ Index] [ Report an Error]