EZ5 MIB Catalog

CISCO-SERVICE-CONTROL-ATTACK-MIB

2013-08-16

This MIB provides data related to different types of attacks detected by a service control entity. A service control entity is a network device which monitors and controls traffic. The service control entity is used as a platform for different service control applications which may perform monitoring operations beyond packet counting and delve deeper into the contents of network traffic. It provides programmable stateful inspection of bidirectional traffic flows and maps these flows with user/subscriber ownership. An attack is a malicious network activity with certain traffic characteristics and which is targeted on a certain network entity. An attack can be identified by its type, direction, source address, destination address and ports. Once an attack is detected, an attack filter is activated based on the type of the attack and corresponding actions are taken in the monitored network - this is referred to as attack start. For example the attack filter can drop the attacking traffic. When the attack detector identifies that the attack characteristics are no longer exist, it ends the mitigation action - what is referred to as attack end. The attack mitigation action is also referred to as attack filtering in this MIB. The time duration of attack filtering between attack start to attack end along with the direction (upstream, downstream) is also maintained by the service control entity. Attack filtering can be applied from the subscriber side to the network side, in the upstream direction. The downstream attack filtering is done from the network side to the subscriber side. This MIB also defines notifications generated by the service control entity when an attack is detected on a monitored network.

Download CISCO-SERVICE-CONTROL-ATTACK-MIB.txt Open CISCO-SERVICE-CONTROL-ATTACK-MIB.txt in a new tab

SCALARS (11) · TABLES (2) · TRAPS (2)

Scalars (11)

NameOID
cscaType1.3.6.1.4.1.9.9.693.1.1.1
cscaSourceAddressType1.3.6.1.4.1.9.9.693.1.1.2
cscaSourceAddress1.3.6.1.4.1.9.9.693.1.1.3
cscaDestinationAddressType1.3.6.1.4.1.9.9.693.1.1.4
cscaDestinationAddress1.3.6.1.4.1.9.9.693.1.1.5
cscaAttackedPort1.3.6.1.4.1.9.9.693.1.1.6
cscaFilterStatus1.3.6.1.4.1.9.9.693.1.1.7
cscaNotifsEnabled1.3.6.1.4.1.9.9.693.1.1.8
cscaLastDiscontinuityTimeStamp1.3.6.1.4.1.9.9.693.1.1.9
cscaGlobalAttackType1.3.6.1.4.1.9.9.693.1.1.10
cscaGlobalAttackNotifsEnabled1.3.6.1.4.1.9.9.693.1.1.11

Tables (2)

NameOID
cscaTypeTable1.3.6.1.4.1.9.9.693.1.2
cscaInfoTable1.3.6.1.4.1.9.9.693.1.3

Traps (2)

NameOID
cscaFilterChange1.3.6.1.4.1.9.9.693.0.1
cscaGlobalAttackFilterChange1.3.6.1.4.1.9.9.693.0.2

END OF TOC

Scalar details

cscaType

1.3.6.1.4.1.9.9.693.1.1.1

CscaAttackTypeA value which identifies the various attack types which may be detected by the service control entity. · Integer32 · hint d

This object indicates the type of an attack detected and reported by the service control entity. There are numerous attack types, based on the service control entity's definition. The service control entity monitors and mitigates a predefined set of attack type. The value of this object should be used as index to table cscaTypeTable in order to query for information regarding this attack type, such as its name and other statistics.

cscaSourceAddressType

1.3.6.1.4.1.9.9.693.1.1.2

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

This object indicates the address type for cscaSourceAddress.

cscaSourceAddress

1.3.6.1.4.1.9.9.693.1.1.3

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

This object indicates the network address that is the source end point of this attack.

cscaDestinationAddressType

1.3.6.1.4.1.9.9.693.1.1.4

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

This object indicates the address type for cscaDestinationAddress.

cscaDestinationAddress

1.3.6.1.4.1.9.9.693.1.1.5

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

This object indicates the network address that is the destination end point of this attack.

cscaAttackedPort

1.3.6.1.4.1.9.9.693.1.1.6

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

This object indicates the port on which this attack occurs, if relevant for this type of attack.

cscaFilterStatus

1.3.6.1.4.1.9.9.693.1.1.7

INTEGER1 = activated2 = deactivated · Integer32

This object indicates the status of the filter for this attack. The values for this object are '1' (activated) and '2' (de-activated).

cscaNotifsEnabled

1.3.6.1.4.1.9.9.693.1.1.8

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object specifies whether the system generates the cscaFilterChange notification.

cscaLastDiscontinuityTimeStamp

1.3.6.1.4.1.9.9.693.1.1.9

TimeStampThe value of the sysUpTime object at which a specific occurrence happened. The specific occurrence must be defined in the description of any object defined using this type. If sysUpTime is reset to zero as a result of a re- initialization of the network management (sub)system, then the values of all TimeStamp objects are also reset. However, after approximately 497 days without a re- initialization, the sysUpTime object will reach 2^^32-1 and then increment around to zero; in this case, existing values of TimeStamp objects do not change. This can lead to ambiguities in the value of TimeStamp objects. · TimeTicks

This object indicates the value of sysUpTime when the last discontinuity occurred.

cscaGlobalAttackType

1.3.6.1.4.1.9.9.693.1.1.10

INTEGER1 = icmpAttack2 = udpAttack3 = udpFragmentAttack4 = tcpSynAttack5 = tcpRstAttack6 = tcpFragmentAttack7 = tcpNonSynAttack · Integer32

This object indicates the type of a global attack detected and reported by the service control entity. The list of the various global attack are: ICMP attack(1) UDP attack(2) UDP fragment attack(3) TCP SYN Attack(4) TCP RST Attack(5) TCP fragment Attack(6) TCP NON-SYN Attack(7)

cscaGlobalAttackNotifsEnabled

1.3.6.1.4.1.9.9.693.1.1.11

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object specifies whether the system generates the cscaGlobalAttackFilterChange notification. Setting this object value to 'true' will enable generation of cscaGlobalAttackFilterChange notification. Setting this object value to 'false' will disable generation of cscaGlobalAttackFilterChange notification.

Table details

cscaTypeTable

1.3.6.1.4.1.9.9.693.1.2

Index: entPhysicalIndex · cscaTypeIndex

This table lists the aggregated statistics for each detected attack in a network controlled by a service control entity.

from ENTITY-MIB

entPhysicalIndex

PhysicalIndexAn arbitrary value that uniquely identifies the physical entity. The value should be a small positive integer. Index values for different physical entities are not necessarily contiguous. (1..2147483647) · Integer32 · hint d

The index for this entry.

cscaTypeIndex

1.3.6.1.4.1.9.9.693.1.2.1.1

CscaAttackTypeA value which identifies the various attack types which may be detected by the service control entity. (1..64) · Integer32 · hint d

This object uniquely identifies the attack type.

cscaTypeCurrentNumAttacks

1.3.6.1.4.1.9.9.693.1.2.1.2

Gauge32 · attacks

This object indicates the current number of ongoing attacks of this type, that the service control entity has detected in the network.

cscaTypeTotalNumAttacks

1.3.6.1.4.1.9.9.693.1.2.1.3

Counter32 · attacks

This object indicates the total number of attacks of this type since the last discontinuity.

cscaTypeTotalNumFlows

1.3.6.1.4.1.9.9.693.1.2.1.4

Counter64 (0..18446744073709551615) · IP flows

This object indicates the total number of IP flows on which this type of attack has been detected, since the last discontinuity.

cscaTypeTotalNumSeconds

1.3.6.1.4.1.9.9.693.1.2.1.5

Counter32 · seconds

This object indicates the accumulated duration in seconds belonging to this attack type, since the last discontinuity.

cscaTypeOriginatedByNetworkSide

1.3.6.1.4.1.9.9.693.1.2.1.6

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object indicates whether this attack type is originated from the Network side or from the Subscriber side.

cscaTypeProtocol

1.3.6.1.4.1.9.9.693.1.2.1.7

Integer32

This enumerated object indicates the protocol type for this type of attack (TCP/UDP/ICMP/etc). The values for this object are: (1) TCP (2) UDP (3) ICMP (4) Other

cscaTypeIsPortSpecific

1.3.6.1.4.1.9.9.693.1.2.1.8

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object indicates whether the attack type is port-specific or not.

cscaTypeIPsDetected

1.3.6.1.4.1.9.9.693.1.2.1.9

Integer32

This object indicates which IPs are detected in this type of attack. The enumerated values are: (1) Originating Side IP is detected. (2) Attacked Side IP is detected. (3) Both side IPs are detected.

cscaInfoTable

1.3.6.1.4.1.9.9.693.1.3

Index: entPhysicalIndex

This table lists information for attack mitigation, also referred to as attack filtering, done by a service control entity in the monitored network.

from ENTITY-MIB

entPhysicalIndex

PhysicalIndexAn arbitrary value that uniquely identifies the physical entity. The value should be a small positive integer. Index values for different physical entities are not necessarily contiguous. (1..2147483647) · Integer32 · hint d

The index for this entry.

cscaInfoUpStreamAttackFilteringTime

1.3.6.1.4.1.9.9.693.1.3.1.1

Counter32 · seconds

This object indicates the cumulative time during which attacks in the up-stream direction were filtered.

cscaInfoUpStreamLastAttackFilteringTime

1.3.6.1.4.1.9.9.693.1.3.1.2

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

This object indicates the time since the previous attack in the upstream direction has ended. Attack end is reached when the service control entity attack detector identifies that the attack characteristics (like high flow rate) no longer exist, and the attack is suppressed in the up-stream traffic.

cscaInfoDownStreamAttackFilteringTime

1.3.6.1.4.1.9.9.693.1.3.1.3

Counter32 · seconds

This object indicates the cumulative time during which attacks in the down-stream direction were filtered.

cscaInfoDownStreamLastAttackFilteringTime

1.3.6.1.4.1.9.9.693.1.3.1.4

TimeIntervalA period of time, measured in units of 0.01 seconds. (0..2147483647) · Integer32

This object indicates the time since the previous attack in the downstream direction has ended. Attack end is reached when the service control entity attack detector identifies that the attack characteristics (like high flow rate) no longer exist, and the attack is suppressed in the down-stream traffic.

Trap details

cscaFilterChange

1.3.6.1.4.1.9.9.693.0.1

The system generates this notification to indicate that the cscaFilterStatus of the attack filter for cscaType has changed due to the reason determined by cscaDescription. The system limits the generation of this notifications for the same cscaType to a five-second interval.

entPhysicalName

1.3.6.1.2.1.47.1.1.1.1.7

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The textual name of the physical entity. The value of this object should be the name of the component as assigned by the local device and should be suitable for use in commands entered at the device's 'console'. This might be a text name (e.g., 'console') or a simple component number (e.g., port or module number, such as '1'), depending on the physical component naming syntax of the device. If there is no local name, or if this object is otherwise not applicable, then this object contains a zero-length string. Note that the value of entPhysicalName for two physical entities will be the same in the event that the console interface does not distinguish between them, e.g., slot-1 and the card in slot-1.

cscaType

1.3.6.1.4.1.9.9.693.1.1.1

CscaAttackTypeA value which identifies the various attack types which may be detected by the service control entity. · Integer32 · hint d

This object indicates the type of an attack detected and reported by the service control entity. There are numerous attack types, based on the service control entity's definition. The service control entity monitors and mitigates a predefined set of attack type. The value of this object should be used as index to table cscaTypeTable in order to query for information regarding this attack type, such as its name and other statistics.

cscaSourceAddressType

1.3.6.1.4.1.9.9.693.1.1.2

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

This object indicates the address type for cscaSourceAddress.

cscaSourceAddress

1.3.6.1.4.1.9.9.693.1.1.3

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

This object indicates the network address that is the source end point of this attack.

cscaDestinationAddressType

1.3.6.1.4.1.9.9.693.1.1.4

InetAddressType0 = unknown1 = ipv42 = ipv63 = ipv4z4 = ipv6z16 = dnsA value that represents a type of Internet address. unknown(0) An unknown address type. This value MUST be used if the value of the corresponding InetAddress object is a zero-length string. It may also be used to indicate an IP address that is not in one of the formats defined below. ipv4(1) An IPv4 address as defined by the InetAddressIPv4 textual convention. ipv6(2) An IPv6 address as defined by the InetAddressIPv6 textual convention. ipv4z(3) A non-global IPv4 address including a zone index as defined by the InetAddressIPv4z textual convention. ipv6z(4) A non-global IPv6 address including a zone index as defined by the InetAddressIPv6z textual convention. dns(16) A DNS domain name as defined by the InetAddressDNS textual convention. Each definition of a concrete InetAddressType value must be accompanied by a definition of a textual convention for use with that InetAddressType. To support future extensions, the InetAddressType textual convention SHOULD NOT be sub-typed in object type definitions. It MAY be sub-typed in compliance statements in order to require only a subset of these address types for a compliant implementation. Implementations must ensure that InetAddressType objects and any dependent objects (e.g., InetAddress objects) are consistent. An inconsistentValue error must be generated if an attempt to change an InetAddressType object would, for example, lead to an undefined InetAddress value. In particular, InetAddressType/InetAddress pairs must be changed together if the address type changes (e.g., from ipv6(2) to ipv4(1)). · Integer32

This object indicates the address type for cscaDestinationAddress.

cscaDestinationAddress

1.3.6.1.4.1.9.9.693.1.1.5

InetAddressDenotes a generic Internet address. An InetAddress value is always interpreted within the context of an InetAddressType value. Every usage of the InetAddress textual convention is required to specify the InetAddressType object that provides the context. It is suggested that the InetAddressType object be logically registered before the object(s) that use the InetAddress textual convention, if they appear in the same logical row. The value of an InetAddress object must always be consistent with the value of the associated InetAddressType object. Attempts to set an InetAddress object to a value inconsistent with the associated InetAddressType must fail with an inconsistentValue error. When this textual convention is used as the syntax of an index object, there may be issues with the limit of 128 sub-identifiers specified in SMIv2, STD 58. In this case, the object definition MUST include a 'SIZE' clause to limit the number of potential instance sub-identifiers; otherwise the applicable constraints MUST be stated in the appropriate conceptual row DESCRIPTION clauses, or in the surrounding documentation if there is no single DESCRIPTION clause that is appropriate. SIZE (0..255) · OCTET STRING

This object indicates the network address that is the destination end point of this attack.

cscaAttackedPort

1.3.6.1.4.1.9.9.693.1.1.6

InetPortNumberRepresents a 16 bit port number of an Internet transport layer protocol. Port numbers are assigned by IANA. A current list of all assignments is available from <http://www.iana.org/>. The value zero is object-specific and must be defined as part of the description of any object that uses this syntax. Examples of the usage of zero might include situations where a port number is unknown, or when the value zero is used as a wildcard in a filter.Reference: STD 6 (RFC 768), STD 7 (RFC 793) and RFC 2960 (0..65535) · Unsigned32 · hint d

This object indicates the port on which this attack occurs, if relevant for this type of attack.

cscaFilterStatus

1.3.6.1.4.1.9.9.693.1.1.7

INTEGER1 = activated2 = deactivated · Integer32

This object indicates the status of the filter for this attack. The values for this object are '1' (activated) and '2' (de-activated).

cscaGlobalAttackFilterChange

1.3.6.1.4.1.9.9.693.0.2

The notification is generated when a start or end of a global attack is detected in the system. Below fields are sent with the trap: entPhysicalName indicates the name of the originating physical entity. cscaGlobalAttackType indicates the type of the global attack. cscaFilterStatus indicates whether the global attack is started or ended ie. the attack filter status is activated or deactivated. cscaTypeOriginatedByNetworkSide indicates the origin/source of the attack, whether it originated from network or subscriber side.

entPhysicalName

1.3.6.1.2.1.47.1.1.1.1.7

SnmpAdminStringAn octet string containing administrative information, preferably in human-readable form. To facilitate internationalization, this information is represented using the ISO/IEC IS 10646-1 character set, encoded as an octet string using the UTF-8 transformation format described in [RFC2279]. Since additional code points are added by amendments to the 10646 standard from time to time, implementations must be prepared to encounter any code point from 0x00000000 to 0x7fffffff. Byte sequences that do not correspond to the valid UTF-8 encoding of a code point or are outside this range are prohibited. The use of control codes should be avoided. When it is necessary to represent a newline, the control code sequence CR LF should be used. The use of leading or trailing white space should be avoided. For code points not directly supported by user interface hardware or software, an alternative means of entry and display, such as hexadecimal, may be provided. For information encoded in 7-bit US-ASCII, the UTF-8 encoding is identical to the US-ASCII encoding. UTF-8 may require multiple bytes to represent a single character / code point; thus the length of this object in octets may be different from the number of characters encoded. Similarly, size constraints refer to the number of encoded octets, not the number of characters represented by an encoding. Note that when this TC is used for an object that is used or envisioned to be used as an index, then a SIZE restriction MUST be specified so that the number of sub-identifiers for any object instance does not exceed the limit of 128, as defined by [RFC3416]. Note that the size of an SnmpAdminString object is measured in octets, not characters. SIZE (0..255) · OCTET STRING · hint 255t

The textual name of the physical entity. The value of this object should be the name of the component as assigned by the local device and should be suitable for use in commands entered at the device's 'console'. This might be a text name (e.g., 'console') or a simple component number (e.g., port or module number, such as '1'), depending on the physical component naming syntax of the device. If there is no local name, or if this object is otherwise not applicable, then this object contains a zero-length string. Note that the value of entPhysicalName for two physical entities will be the same in the event that the console interface does not distinguish between them, e.g., slot-1 and the card in slot-1.

cscaGlobalAttackType

1.3.6.1.4.1.9.9.693.1.1.10

INTEGER1 = icmpAttack2 = udpAttack3 = udpFragmentAttack4 = tcpSynAttack5 = tcpRstAttack6 = tcpFragmentAttack7 = tcpNonSynAttack · Integer32

This object indicates the type of a global attack detected and reported by the service control entity. The list of the various global attack are: ICMP attack(1) UDP attack(2) UDP fragment attack(3) TCP SYN Attack(4) TCP RST Attack(5) TCP fragment Attack(6) TCP NON-SYN Attack(7)

cscaFilterStatus

1.3.6.1.4.1.9.9.693.1.1.7

INTEGER1 = activated2 = deactivated · Integer32

This object indicates the status of the filter for this attack. The values for this object are '1' (activated) and '2' (de-activated).

cscaTypeOriginatedByNetworkSide

1.3.6.1.4.1.9.9.693.1.2.1.6

TruthValue1 = true2 = falseRepresents a boolean value. · Integer32

This object indicates whether this attack type is originated from the Network side or from the Subscriber side.

↑ To TOC