2.2.15 Ensure 'SEC_PROTOCOL_ERROR_TRACE_ACTION' Is Set to 'LOG'

Information

As bad packets received from the client can potentially indicate packet-based attacks on the system, such as 'TCP SYN Flood' or 'Smurf' attacks, which could result in a Denial-of-Service condition, this diagnostic/logging value for ALERT, LOG, or TRACE conditions should be set according to the needs of the organization.

Solution

To remediate this setting execute the following SQL statement. ALTER SYSTEM SET SEC_PROTOCOL_ERROR_TRACE_ACTION=LOG SCOPE = SPFILE;

See Also

https://workbench.cisecurity.org/files/601