All alerts that have iv_alert.alertType = 21 are NTBA host sweep alerts. Its iv_alert_data.typeSpecific data has the following format:
First byte contains number of the IP information to follow. If there are ten IPs involved in the hostsweep, then the first byte of typeSpecificData will have a value of 10. Every subsequent four bytes will contain the actual IP values.
Total length of typeSpecificData in the above example will be 1 + ( 10* 4) + 8 = 49 bytes.
The details of the alert are as follows:
Number of bytes | Value |
|---|---|
4 | Connection rule ID |
4 | Connection drop count |
1 | External geographical location |
1 | External reputation |
1 | Connection rule type |
4 | Protocol ID |
2 | IP address count |
4 (IPv4) or 16 (IPv6) | Version of the target IP address |
1 | Version information |
4 (IPv4) or 16 (IPv6) | Proxy IP address |
Variable length | Packet log |
.png)