Network violation details
HTTP Slow Loris
-
Consider tuning the incomplete Header Delay (incompHdrDelay) configuration to a smaller value.
-
By default, the NetScaler instance drops these incomplete requests.
-
The affected application. You can also select the application from the list if two or more applications are affected with violations.
-
The graph indicating all violations
-
The violation occurrence time
-
The detection message indicating the total incomplete requests as Slow Loris attack
DNS Slow Loris
-
The affected application. You can also select the application from the list if two or more applications are affected with violations.
-
The graph indicating all violations
-
The violation occurrence time
-
The detection message indicating the total DNS requests as Slow Loris attack
HTTP Slow Post
-
The affected application. You can also select the application from the list if two or more applications are affected with violations.
-
The graph indicating all violations
-
The violation occurrence time
-
The detection message indicating the total POST requests as Slow Loris attack
NXDOMAIN Flood Attack
-
Check for unusually high resource consumption on both DNS server and DNS proxy server.
-
Enforce a limit for request rate on NetScaler instance
-
Isolate and block suspect client IP addresses
-
If most names result in NXDOMAIN, follow an identifiable pattern and configure DNS policies to drop such requests
-
To conserve memory for genuine DNS records, configure a limit for negative records on NetScaler instance. For more information, see Mitigate DNS DDoS attacks.
-
The affected application. You can also select the application from the list if two or more applications are affected with violations.
-
The graph indicating all violations
HTTP Desync Attack
-
A single request to the front-end server (virtual server)
-
2 requests to the back-end server
-
Content length and transfer encoding headers in a single HTTP transaction
-
Multiple content-length headers with different values in a single HTTP transaction

-
The affected application. You can also select the application from the list if two or more applications are affected with this violation.
-
The graph indicating the violation details. Hover the mouse pointer on the bar graph to view the total invalid requests/reponses.
-
The detection message for the violation, indicating the total requests/responses:
-
Containing multiple content-length headers with different values
-
Containing both content length and transfer encoding headers
-
Bleichenbacher Attack
-
The affected application. You can also select the application from the list if two or more applications are affected with this violation.
-
The graph indicating the violation details. Hover the mouse point on the bar graph to view the total erroneous handshake connections detected.
-
The detection message for the violation, indicating the total handshake connections on the virtual server with erroneous encrypted data.
Segment Smack Attack
-
The affected NetScaler instance
-
The graph indicating the violation details. Hover the mouse point on the bar graph to view the total number of bad client connections detected.
-
The detection message for the violation, indicating the total client connections dropped.

SYN Flood Attack
-
The affected application. You can also select the application from the list if two or more applications are affected with this violation
-
The graph indicating the SYN attack details
-
The detection message, indicating the total number of times that the application is detected with SYN attack
Small Window Attack
-
The affected application. You can also select the application from the list if two or more applications are affected with this violation.
-
The graph indicating the attack details. Hover the mouse point on the bar graph to view the total number of TCP small window packets detected.
-
The detection message indicating the total TCP small window packets dropped.