Attack Behavior
In a malformed packet attack, the attacker sends defective IP packets to the target switch to make the switch crash.
Abnormal packet attacks are classified into the following types:
-
Flood attack without IP payload
-
IGMP null packet attack
-
Local Area Network Denial (LAND) attack
-
Smurf attack
-
Invalid TCP flag attack
Security Policy
To protect switches against breakdowns caused by malformed packet attacks and to ensure non-stop network services, configure defense against malformed packet attacks. Switches enabled with this defense function can identify and discard malformed packets.
Configuration Method
Enable defense against malformed packet attacks. By default, this function is enabled.
<HUAWEI> system-view [HUAWEI] anti-attack abnormal enable
