GEN:SID 1:375
Message ICMP PING LINUX/*BSD
Summary This event is generated when an ICMP echo request is made from a Linux or Berkeley Systems Development (BSD) host running the reconnaissance tool SING.
Impact Information gathering.  An ICMP echo request can determine if a host is active.
Detailed Information An ICMP echo request is used by the ping command to elicit an ICMP echo reply from a listening live host.  An echo request that originates from a host running Linux or BSD using the SING reconnaissance tool contains a unique payload in the message request.
Affected Systems All
Attack Scenarios An attacker may attempt to determine live hosts in a network prior to launching an attack.
Ease of Attack Simple
Corrective Action Block inbound ICMP echo requests.
Additional References Arachnids:
http://www.whitehats.com/info/IDS447
Rule References arachnids: 447