Welcome to Linux Forums!

With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.

Linux Forum ArticlesLinux ForumsLinux Forum DownloadsLinux Hosts
Home|Register|FAQ|Member List|Calendar|Unanswered Posts|Forum Rules|Today's Posts|Advanced Search|
SEARCH FOR IN
Go Back   Linux Forums > GNU Linux Zone > Linux Security
Reload this Page Snort - How to reduce false positives???
Linux Forums
Linux Forums
Welcome To The Linux Forums!
Welcome to Linux Forums. We pride ourselves in being one of the largest Linux communities on the web, we encourage you to REGISTER on our forums and participate in the community. There are over 150,000 members ready to answer your questions. JOINING US today will allow you to make new posts, get support, send messages to other members and submit downloads to our downloads directory and many other great features!

Linux Security Discussion about keeping your machines secure, and the crackers out.

Reply
 
Thread Tools Display Modes
Old 05-12-2008   #1 (permalink)
Saltamontes
Just Joined!
 
Join Date: Oct 2007
Location: Mexico
Posts: 42
Snort - How to reduce false positives???

Hello to everybody

After been experimenting with Sgui/Snort i have all parts working, and a sensor installed in the site capturing data from the whole network, but i have seen, from days ago to today, many false positives, some like portscans, backdoors, "double decode attack", and alerts like "WEB-MISC ...","WEB-PHP ... access", "portscan: TCP Portsweep" anh others of the simmilar kind.

"WEB-CGI ... access","WEB-PHP ... access","WEB-FRONTPAGE ... access", "WEB-IIS view source..." are file upload from local machines to the local web site.

"http_inspect: BARE BYTE UNICODE ENCODING" and "http_inspect: OVERSIZE REQUEST-URY DIRECTORY" are searches or quueries over the local web site.

"portscan: OPEN PORT" don't shows nothing on the payload section and "portscan: TCP PortSweep" shows HTTP ports, OpenPorts and PortSweep scans are done to a common IP, i think that is a Web server (Apache or IIS)...

then how can i add some rules or restrictions in order to avoid generate or show that alerts???

i supose that chould add some in the sfportscan section ignore_scanners{} or ignore_scanned {} from snort.conf, but i don't know if only adding the IP from the web server will be enough. The Snort Manual PDF don't have enough information.

...and there are other alerts like "http_inspect: DOUBLE DECODING ATTACK" from local IPs to other IPs (i don't know if are part of local network ranges)

it's possible to reduce that kind of false positives but keeping the true alerts???

i will aprecciate any idea or guide.

Thanks to everybody.

See you
Saltamontes is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT. The time now is 06:14 AM.

Powered by vBulletin 3.6.8 ©2000 - 2007, content relevant URLs by vBSEO, Property of Core Root.

Content Relevant URLs by vBSEO 3.0.0