CISCO-SERVICE-CONTROL-ATTACK-MIB
This MIB provides data related to different types of
attacks detected by a service control entity.
A service control entity is a network device which monitors and
controls traffic. The service control entity is used as a
platform for different service control applications which may
perform monitoring operations beyond packet counting and delve
deeper into the contents of network traffic. It provides
programmable stateful inspection of bidirectional
traffic flows and maps these flows with user/subscriber
ownership.
An attack is a malicious network activity with certain traffic
characteristics and which is targeted on a certain network
entity. An attack can be identified by its type, direction,
source address, destination address and ports.
Once an attack is detected, an attack filter is activated based
on the type of the attack and corresponding actions are taken
in
the monitored network - this is referred to as attack start.
For example the attack filter can drop the attacking traffic.
When the attack detector identifies that the attack
characteristics are no longer exist, it ends the mitigation
action - what is referred to as attack end. The attack
mitigation action is also referred to as attack filtering in
this MIB.
The time duration of attack filtering between attack start to
attack end along with the direction (upstream, downstream) is
also maintained by the service control entity. Attack
filtering
can be applied from the subscriber side to the network side, in
the upstream direction. The downstream attack filtering is
done
from the network side to the subscriber side.
This MIB also defines notifications generated by the service
control entity when an attack is detected on a monitored
network.
- Source file
CISCO-SERVICE-CONTROL-ATTACK-MIB- Last revised
- Identity
ciscoServiceControlAttackMIB- Base OID
1.3.6.1.4.1.9.9.693
Imported Objects
| CISCO-SMI | ciscoMgmt |
| ENTITY-MIB | entPhysicalIndex entPhysicalName |
| INET-ADDRESS-MIB | InetAddress InetAddressType InetPortNumber |
| SNMPv2-CONF | MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page) |
| SNMPv2-SMI | Counter32 Counter64 Gauge32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-IDENTITY (no object page) OBJECT-TYPE (no object page) Unsigned32 |
| SNMPv2-TC | AutonomousType TEXTUAL-CONVENTION (no object page) TimeInterval TimeStamp TruthValue |
Net-SNMP examples using the cisco MIB directory Show commands
These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.
Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-SERVICE-CONTROL-ATTACK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-SERVICE-CONTROL-ATTACK-MIB::ciscoServiceControlAttackMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-SERVICE-CONTROL-ATTACK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-SERVICE-CONTROL-ATTACK-MIB::ciscoServiceControlAttackMIB'
Objects (35)
Showing 35 of 35 objects
Object legend
Object type
Icons distinguish tables, entry rows, columns, scalars, and structural nodes.
SNMPv2-TCTruthValue
Syntax
Blue badges identify the value syntax. Connected badges read as defining module and convention.
IF-MIBifIndex
Table index
Green identifies an index object; yellow names its module when the index is defined elsewhere.
r/w
deprecated
obsolete
Access and status
r/w means read-write. Grey labels mark definitions retained for compatibility.
OBS ✓
Observium use
The indicator appears only when Observium directly references that object.
ifOperStatus
.1.3.6.1.2.1…
Names and OIDs
Object names link to their detail pages. Hover or focus a linked name or badge for available definition details.
.1.3.6.1.4.1.9.9.693 |
||
.1.3.6.1.4.1.9.9.693.0 |
||
.1.3.6.1.4.1.9.9.693.1 |
||
.1.3.6.1.4.1.9.9.693.1.1 |
||
.1.3.6.1.4.1.9.9.693.1.1.1 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.693.1.1.10 |
|
.1.3.6.1.4.1.9.9.693.1.1.11 |
||
.1.3.6.1.4.1.9.9.693.1.1.2 |
||
.1.3.6.1.4.1.9.9.693.1.1.3 |
||
.1.3.6.1.4.1.9.9.693.1.1.4 |
||
.1.3.6.1.4.1.9.9.693.1.1.5 |
||
.1.3.6.1.4.1.9.9.693.1.1.6 |
||
|
Enumeration
|
.1.3.6.1.4.1.9.9.693.1.1.7 |
|
.1.3.6.1.4.1.9.9.693.1.1.8 |
||
.1.3.6.1.4.1.9.9.693.1.1.9 |
||
.1.3.6.1.4.1.9.9.693.1.2 |
||
.1.3.6.1.4.1.9.9.693.1.2.1 |
||
|
Integer32
|
.1.3.6.1.4.1.9.9.693.1.2.1.1 |
|
|
attacksSNMPv2-SMIGauge32
|
.1.3.6.1.4.1.9.9.693.1.2.1.2 |
|
|
attacksSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.693.1.2.1.3 |
|
|
IP flowsSNMPv2-SMICounter64
|
.1.3.6.1.4.1.9.9.693.1.2.1.4 |
|
|
secondsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.693.1.2.1.5 |
|
.1.3.6.1.4.1.9.9.693.1.2.1.6 |
||
.1.3.6.1.4.1.9.9.693.1.2.1.7 |
||
.1.3.6.1.4.1.9.9.693.1.2.1.8 |
||
.1.3.6.1.4.1.9.9.693.1.2.1.9 |
||
.1.3.6.1.4.1.9.9.693.1.3 |
||
.1.3.6.1.4.1.9.9.693.1.3.1 |
||
|
secondsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.693.1.3.1.1 |
|
.1.3.6.1.4.1.9.9.693.1.3.1.2 |
||
|
secondsSNMPv2-SMICounter32
|
.1.3.6.1.4.1.9.9.693.1.3.1.3 |
|
.1.3.6.1.4.1.9.9.693.1.3.1.4 |
||
.1.3.6.1.4.1.9.9.693.2 |
||
.1.3.6.1.4.1.9.9.693.2.1 |
||
.1.3.6.1.4.1.9.9.693.2.2 |
Dependencies (9) 6 direct · 3 transitive Show tree and compile order Hide dependency details
Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.
Dependency tree
Dependency-first compile order
- SNMPv2-SMIrfc
- CISCO-SMIcisco
- SNMPv2-TCrfc
- IANA-ENTITY-MIBrfc
- SNMPv2-CONFrfc
- SNMP-FRAMEWORK-MIBrfc
- UUID-TC-MIBrfc
- ENTITY-MIBrfc
- INET-ADDRESS-MIBrfc
- CISCO-SERVICE-CONTROL-ATTACK-MIBciscoselected
Type Definitions (1)
| Integer32 |
Conformance Groups (8)
|
cscaTypeCurrentNumAttacks cscaTypeTotalNumAttacks cscaTypeTotalNumFlows cscaTypeTotalNumSeconds cscaTypeOriginatedByNetworkSide cscaTypeProtocol cscaTypeIsPortSpecific cscaTypeIPsDetected
A collection of objects which provides attack information.
|
.1.3.6.1.4.1.9.9.693.2.2.1
|
|
|
cscaInfoUpStreamAttackFilteringTime cscaInfoUpStreamLastAttackFilteringTime cscaInfoDownStreamAttackFilteringTime cscaInfoDownStreamLastAttackFilteringTime
A collection of objects which provides attack filtering times
for upstream and down stream attacks. |
.1.3.6.1.4.1.9.9.693.2.2.2
|
|
|
cscaMIBNotificationGroup
deprecated
|
A collection of notification which provides status change
information for attack filters. cscaMIBNotificationGroup object is superseded by cscaMIBNotificationGroupRev1. |
.1.3.6.1.4.1.9.9.693.2.2.3
|
|
cscaFilterObjectGroup
deprecated
|
cscaType cscaSourceAddressType cscaSourceAddress cscaDestinationAddressType cscaDestinationAddress cscaAttackedPort cscaFilterStatus cscaLastDiscontinuityTimeStamp
A collection of objects which define each attack filter and
its status. cscaFilterObjectGroup object is superseded by cscaFilterObjectGroupRev1. |
.1.3.6.1.4.1.9.9.693.2.2.4
|
|
cscaMIBNotifControlGroup
deprecated
|
A collection of object(s) to control the enable/disable
state of notification generation. cscaMIBNotifControlGroup object is superseded by cscaMIBNotifControlGroupRev1. |
.1.3.6.1.4.1.9.9.693.2.2.5
|
|
A collection of notification which provides status change
information for both specific IP and global attack filters. |
.1.3.6.1.4.1.9.9.693.2.2.6
|
|
|
cscaType cscaSourceAddressType cscaSourceAddress cscaDestinationAddressType cscaDestinationAddress cscaAttackedPort cscaFilterStatus cscaLastDiscontinuityTimeStamp cscaGlobalAttackType
A collection of objects which define each attack filter and
its status. |
.1.3.6.1.4.1.9.9.693.2.2.7
|
|
|
A collection of object(s) to control the enable/disable
state of notification generation. |
.1.3.6.1.4.1.9.9.693.2.2.8
|
Compliance Statements (2)
OID
.1.3.6.1.4.1.9.9.693.2.1.1The compliance statement for SNMP Agents which implement this
MIB.
MIB.
Required groups
| mandatory | cscaMIBAttackTypeObjectGroup | |
| mandatory | cscaMIBNotificationGroup | |
| mandatory | cscaMIBAttackInfoObjectGroup | |
| mandatory | cscaFilterObjectGroup | |
| mandatory | cscaMIBNotifControlGroup |
OID
.1.3.6.1.4.1.9.9.693.2.1.2The compliance statement for SNMP Agents which implement this
generic filter (both Specific IP and global attack) MIB.
generic filter (both Specific IP and global attack) MIB.
Required groups
| mandatory | cscaMIBAttackTypeObjectGroup | |
| mandatory | cscaMIBNotificationGroupRev1 | |
| mandatory | cscaMIBAttackInfoObjectGroup | |
| mandatory | cscaFilterObjectGroupRev1 | |
| mandatory | cscaMIBNotifControlGroupRev1 |
Notifications / Traps (2)
| Name | OID | Description |
|---|---|---|
.1.3.6.1.4.1.9.9.693.0.1 |
The system generates this notification to indicate that the
cscaFilterStatus of the attack filter for cscaType has changed due to the reason determined by cscaDescription. The system limits the generation of this notifications for the same cscaType to a five-second interval. |
|
.1.3.6.1.4.1.9.9.693.0.2 |
The notification is generated when a start or end of a global
attack is detected in the system. Below fields are sent with the trap: entPhysicalName indicates the name of the originating physical entity. cscaGlobalAttackType indicates the type of the global attack. cscaFilterStatus indicates whether the global attack is started or ended ie. the attack filter status is activated or deactivated. cscaTypeOriginatedByNetworkSide indicates the origin/source of the attack, whether it originated from network or subscriber side. |