Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Users
[Top] [All Lists]

[Snort-users] False positive alerts - rules fire on unmatching payload

Subject: [Snort-users] False positive alerts - rules fire on unmatching payload
Date: Thu, 11 May 2006 18:07:22 -0400
I just turned on the new spyware-put rules.  Since most of those rules
are looking at User-Agent strings, I would expect a fairly low false
positive rate.  In most cases when I look at the payload, I see what
made the rule fire, like FunWebProducts or similar.  But, many times
neither FunWebProducts or User-Agent is even present in the payload.
I'm referring to sid 5856 now, but it really doesn't matter.  The
general problem is that Snort sometimes alerts when the data does not
match the rule that fired.  Usually, I can confirm that there was
traffic between the two hosts reported in the alert and at the time of
the alert.  But, the payload just doesn't match at all.  I've been
working with Snort for over two years now and have seen this problem
through each version that I've installed, and keep hoping that it will
be better in the next release.  Our current sensor is running
comfortably with the snort process taking up about 30% of the CPU and
4.5% of the memory.  The drop is usually less than 0.5%.  So, I don't
think there's a loading problem.  And even if there was, I can't see how
it would explain this problem.  Any thoughts?

--Dave
<Prev in Thread] Current Thread [Next in Thread>
  • [Snort-users] False positive alerts - rules fire on unmatching payload, Humes, David G. <=