Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-users] False positive alerts - rules fire on unmatching payload |
|---|---|
| Date: | Thu, 11 May 2006 18:07:22 -0400 |
I just turned on the new spyware-put rules. Since most of those rules are looking at User-Agent strings, I would expect a fairly low false positive rate. In most cases when I look at the payload, I see what made the rule fire, like FunWebProducts or similar. But, many times neither FunWebProducts or User-Agent is even present in the payload. I'm referring to sid 5856 now, but it really doesn't matter. The general problem is that Snort sometimes alerts when the data does not match the rule that fired. Usually, I can confirm that there was traffic between the two hosts reported in the alert and at the time of the alert. But, the payload just doesn't match at all. I've been working with Snort for over two years now and have seen this problem through each version that I've installed, and keep hoping that it will be better in the next release. Our current sensor is running comfortably with the snort process taking up about 30% of the CPU and 4.5% of the memory. The drop is usually less than 0.5%. So, I don't think there's a loading problem. And even if there was, I can't see how it would explain this problem. Any thoughts? --Dave
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] Why Snort doubles packet number?, Justin Heath |
|---|---|
| Next by Date: | Re: [Snort-users] Compiling snort for CheckPoint Firewall-1 support, carlopmart |
| Previous by Thread: | [Snort-users] Alert not detected once, João Mota |
| Next by Thread: | [Snort-users] unsubscrive, Juliano Murlick |
| Indexes: | [Date] [Thread] [Top] [All Lists] |