description-logoDescription

It indicates detection of Internet Control Message Protocol (ICMP) traffic sent between TFN2K hosts.



Tribal Flood Network (TFN) is a backdoor trojan used for Distributed Denial-of-Service (DDOS) attacks. TFN2K hosts communicate with each other using ICMP messages to launch DDoS attacks.

affected-products-logoAffected Products

Any TFN2K infected system is vulnerable to the attack

Impact logoImpact

Compromised hosts can be used to launch attacks on other systems

recomended-action-logoRecommended Actions

Clean the infected system as soon as possible.


Use FortiGate to block the TFN traffic so as to protect the network.

Coverage

IPS (Regular DB)
IPS (Extended DB)

References

1