kevmap

TechniquesT1499.002 › AN0490

AN0490 Analytic 0490

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Excessive inbound HTTP or TLS connections to services such as Apache or Nginx, causing worker thread exhaustion or segmentation faults.</p>
Detects
T1499.002 Service Exhaustion Flood
Part of
DET0173 Detection Strategy for Endpoint DoS via Service Exhaustion Flood

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLHigh frequency of accept(), read(), or SSL_read() syscalls tied to nginx/apache processesDC0035 Process Access
NSM:FlowSudden spike in incoming flows to web service ports from single/multiple IPsDC0078 Network Traffic Flow
linux:syslogRepetitive HTTP 408, 500, or 503 errors logged within short timeframeDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ErrorCodeWindowTunable count of specific HTTP error codes in timeframe
ConnectionRateThresholdDefines number of connections per second considered anomalous

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-45382D-Link Multiple RoutersMapped
CVE-2022-26258D-Link DIR-820LMapped