[ISSForum] Stream_DoS signature

In its security information that can be found on
http://www.iss.net/security_center/reference/vuln/Stream_DoS.htm, it's
noted that signature only considers ACK packets that are not associated
with an active connection.

But I've found that this signature is triggered whenever the number of ACKs
exceed the pam.flood.ack.limit threshold within pam.flood.ack.interval

Has anyone found the same? Please, correct me if I'm wrong.

Best regards, Sergey V. Soldatov.
tel/fax +7 095 745 89 50 (2663)

