RULE(RULE ID:338572)

Rule General Information
Release Date: 2024-11-26
Rule Name: NAT Slipstreaming Attack Detection
Severity:
CVE ID:
Rule Protection Details
Description: NAT Slipstreaming is a network attack method that exploits the behavior of NAT (network address translation) and firewalls to bypass network border security measures, thereby allowing an attacker to access devices or services inside a protected network. This rule detects the suspicious behavior of REGISTER requests carrying SIP protocol in HTTP requests, which indicates a possible NAT Slipstreaming attack in the environment.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.