Dear Suricata community,
I have activated the stream events rules (I know I shouldn’t because of many false positives), and I get tons of these results:
09/09/2020-05:09:53.894356 [**] [1:2210008:2] SURICATA STREAM 3way handshake SYN resend different seq on SYN recv [**] [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 51.91.21.58:443 -> 188.44.77.158:443
09/09/2020-03:53:02.482568 [**] [1:2210008:2] SURICATA STREAM 3way handshake SYN resend different seq on SYN recv [**] [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 187.193.226.34:53 -> 188.44.77.158:443
09/09/2020-00:04:15.761328 [**] [1:2210008:2] SURICATA STREAM 3way handshake SYN resend different seq on SYN recv [**] [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 74.91.124.9:30120 -> 188.44.77.158:443
09/08/2020-22:37:00.559047 [**] [1:2210008:2] SURICATA STREAM 3way handshake SYN resend different seq on SYN recv [**] [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 172.248.68.59:80 -> 188.44.77.158:443
09/08/2020-14:17:07.687170 [**] [1:2210008:2] SURICATA STREAM 3way handshake SYN resend different seq on SYN recv [**] [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 185.239.242.248:3389 -> 188.44.77.158:443
(just a few examples, many rule hits for each IP).
It’s not that I’m shocked by the large number of rule hits (as I said, I’m aware that there can be lots of false positives). But what’s striking me is the source port - this doesn’t look like normal traffic; why should a connection to my https port come from these well-known ports? And the source ports are almost systematically well-known.
So I wonder what this means - could it be part of something like a ddos scheme - trying to provoke a reply to the (spoofed?) source IP? Does it make sense that in such a case that specific rule is triggered (I only get hits for this one rule). Might it be an idea to turn that rule into a drop rule?
Oh, and it’s only ports 80 and 443, although there are other open ports.
Thanks for any hints!