CISCO-SERVICE-CONTROL-ATTACK-MIB

        This MIB provides data related to different types of
attacks detected by a service control entity.
        
A service control entity is a network device which monitors and
controls traffic.  The service control entity is used as a
platform for different service control applications which may
perform monitoring operations beyond packet counting and delve 
        
deeper into the contents of network traffic.  It provides
programmable stateful inspection of bidirectional
traffic flows and maps these flows with user/subscriber
ownership.
        
An attack is a malicious network activity with certain traffic
characteristics and which is targeted on a certain network
entity.  An attack can be identified by its type, direction,
source address, destination address and ports.
        
Once an attack is detected, an attack filter is activated based
on the type of the attack and corresponding actions are taken
in
the monitored network - this is referred to as attack start. 
For example the attack filter can drop the attacking traffic. 
When the attack detector identifies that the attack
characteristics are no longer exist, it ends the mitigation
action - what is referred to as attack end.  The attack
mitigation action is also referred to as attack filtering in
this MIB.
        
The time duration of attack filtering between attack start to
attack end along with the direction (upstream, downstream) is
also maintained by the service control entity.  Attack
filtering
can be applied from the subscriber side to the network side, in
the upstream direction.  The downstream attack filtering is
done
from the network side to the subscriber side.
        
This MIB also defines notifications generated by the service
control entity when an attack is detected on a monitored
network.
    
Source file
CISCO-SERVICE-CONTROL-ATTACK-MIB
Last revised
Identity
ciscoServiceControlAttackMIB
Base OID
1.3.6.1.4.1.9.9.693
Imported Objects
CISCO-SMI ciscoMgmt
ENTITY-MIB entPhysicalIndex entPhysicalName
INET-ADDRESS-MIB InetAddress InetAddressType InetPortNumber
SNMPv2-CONF MODULE-COMPLIANCE (no object page) NOTIFICATION-GROUP (no object page) OBJECT-GROUP (no object page)
SNMPv2-SMI Counter32 Counter64 Gauge32 Integer32 MODULE-IDENTITY (no object page) NOTIFICATION-TYPE (no object page) OBJECT-IDENTITY (no object page) OBJECT-TYPE (no object page) Unsigned32
SNMPv2-TC AutonomousType TEXTUAL-CONVENTION (no object page) TimeInterval TimeStamp TruthValue
Net-SNMP examples using the cisco MIB directory Show commands

These commands use the standard Observium installation path and load the selected MIB variant before the RFC and Net-SNMP directories.

Translate the module identity
/usr/bin/snmptranslate -Pud -Ir -On -m 'CISCO-SERVICE-CONTROL-ATTACK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'CISCO-SERVICE-CONTROL-ATTACK-MIB::ciscoServiceControlAttackMIB'
Walk the MIB subtree
/usr/bin/snmpbulkwalk -v2c -c '<community>' -Pud -Ir -OQUs -m 'CISCO-SERVICE-CONTROL-ATTACK-MIB' -M '/opt/observium/mibs/cisco:/opt/observium/mibs/rfc:/opt/observium/mibs/net-snmp' 'udp:<hostname>:161' 'CISCO-SERVICE-CONTROL-ATTACK-MIB::ciscoServiceControlAttackMIB'
How SNMP, Net-SNMP, MIB paths, and variants work
Objects (35)
.1.3.6.1.4.1.9.9.693
.1.3.6.1.4.1.9.9.693.0
.1.3.6.1.4.1.9.9.693.1
.1.3.6.1.4.1.9.9.693.1.1
.1.3.6.1.4.1.9.9.693.1.1.1
Enumeration
.1.3.6.1.4.1.9.9.693.1.1.10
.1.3.6.1.4.1.9.9.693.1.1.11
.1.3.6.1.4.1.9.9.693.1.1.2
.1.3.6.1.4.1.9.9.693.1.1.3
.1.3.6.1.4.1.9.9.693.1.1.4
.1.3.6.1.4.1.9.9.693.1.1.5
.1.3.6.1.4.1.9.9.693.1.1.6
Enumeration
.1.3.6.1.4.1.9.9.693.1.1.7
.1.3.6.1.4.1.9.9.693.1.1.8
.1.3.6.1.4.1.9.9.693.1.1.9
.1.3.6.1.4.1.9.9.693.1.2
.1.3.6.1.4.1.9.9.693.1.2.1
Integer32
.1.3.6.1.4.1.9.9.693.1.2.1.1
.1.3.6.1.4.1.9.9.693.1.2.1.2
.1.3.6.1.4.1.9.9.693.1.2.1.3
.1.3.6.1.4.1.9.9.693.1.2.1.4
.1.3.6.1.4.1.9.9.693.1.2.1.5
.1.3.6.1.4.1.9.9.693.1.2.1.6
.1.3.6.1.4.1.9.9.693.1.2.1.7
.1.3.6.1.4.1.9.9.693.1.2.1.8
.1.3.6.1.4.1.9.9.693.1.2.1.9
.1.3.6.1.4.1.9.9.693.1.3
.1.3.6.1.4.1.9.9.693.1.3.1
.1.3.6.1.4.1.9.9.693.1.3.1.1
.1.3.6.1.4.1.9.9.693.1.3.1.2
.1.3.6.1.4.1.9.9.693.1.3.1.3
.1.3.6.1.4.1.9.9.693.1.3.1.4
.1.3.6.1.4.1.9.9.693.2
.1.3.6.1.4.1.9.9.693.2.1
.1.3.6.1.4.1.9.9.693.2.2
Dependencies (9) 6 direct · 3 transitive Show tree and compile order Hide dependency details

Each imported module is resolved in the importing module's source directory first, then through the normal default-variant rules.

Dependency tree
Type Definitions (1)
Integer32
Conformance Groups (8)
A collection of objects which provides attack information.
.1.3.6.1.4.1.9.9.693.2.2.1
A collection of objects which provides attack filtering times
for upstream and down stream attacks.
.1.3.6.1.4.1.9.9.693.2.2.2
A collection of notification which provides status change
information for attack filters.
cscaMIBNotificationGroup object is superseded by
cscaMIBNotificationGroupRev1.
.1.3.6.1.4.1.9.9.693.2.2.3
A collection of objects which define each attack filter and
its status.
cscaFilterObjectGroup object is superseded by
cscaFilterObjectGroupRev1.
.1.3.6.1.4.1.9.9.693.2.2.4
A collection of object(s) to control the enable/disable
state of notification generation.
cscaMIBNotifControlGroup object is superseded by
cscaMIBNotifControlGroupRev1.
.1.3.6.1.4.1.9.9.693.2.2.5
A collection of notification which provides status change
information for both specific IP and global attack filters.
.1.3.6.1.4.1.9.9.693.2.2.6
A collection of objects which define each attack filter and
its status.
.1.3.6.1.4.1.9.9.693.2.2.7
A collection of object(s) to control the enable/disable
state of notification generation.
.1.3.6.1.4.1.9.9.693.2.2.8
Compliance Statements (2)

OID .1.3.6.1.4.1.9.9.693.2.1.1
The compliance statement for SNMP Agents which implement this
MIB.
Required groups

OID .1.3.6.1.4.1.9.9.693.2.1.2
The compliance statement for SNMP Agents which implement this
generic filter (both Specific IP and global attack) MIB.
Required groups
Notifications / Traps (2)
NameOIDDescription
.1.3.6.1.4.1.9.9.693.0.1
The system generates this notification to indicate that the
cscaFilterStatus of the attack filter for cscaType has changed
due to the reason determined by cscaDescription. The system
limits the generation of this notifications for the same
cscaType to a five-second interval.
.1.3.6.1.4.1.9.9.693.0.2
The notification is generated when a start or end of a global
attack is detected in the system.

Below fields are sent with the trap:
entPhysicalName indicates the name of the
originating physical entity.
cscaGlobalAttackType indicates the type of the global
attack.
cscaFilterStatus indicates whether the global attack is
started or ended ie. the attack filter status is activated or
deactivated.
cscaTypeOriginatedByNetworkSide indicates the origin/source
of the attack, whether it originated from network or subscriber
side.