RE: Snort

From: Leon De France (Leon.DeFrance_at_Siebel.com)
Date: 09/30/04

  • Next message: Matt Shelton: "Passive Asset Detection System v1.1.3 Released"
    Date: Thu, 30 Sep 2004 15:53:07 -0600
    To: "Jeremy Gonzales" <jerdgonzales@yahoo.com>, focus-ids@securityfocus.com
    
    

    You can try what was silicon defense's snortsnarf. It will not get rid
    of false positives, but it does a good job with reports imo
    http://www.snort.org/dl/contrib/data_analysis/snortsnarf/

    There is also ACID.

    Leon

    -----Original Message-----
    From: Jeremy Gonzales [mailto:jerdgonzales@yahoo.com]
    Sent: Monday, September 27, 2004 3:09 PM
    To: focus-ids@securityfocus.com
    Subject: Snort

    Hi,

    Does anyone have experience with snort reports? How do
    you deal with the loads of information? Is there a way
    to generate reports that eliminate the false
    positives? Any help will be appreciated.

    Thanks,

    Jeremy.

                    
    __________________________________
    Do you Yahoo!?
    Yahoo! Mail - 50x more storage than other providers!
    http://promotions.yahoo.com/new_mail

    ------------------------------------------------------------------------

    --
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT. Go to
    http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to
    learn more.
    ------------------------------------------------------------------------
    --
    ------------------------------------------------------------------------------
    This e-mail message is for the sole use of the intended recipient(s) and contains confidential and/or privileged information belonging to Siebel Systems, Inc. or its customers or partners.  Any unauthorized review, use, copying, disclosure or distribution of this message is strictly prohibited.  If you are not an intended recipient of this message, please contact the sender by reply e-mail and destroy all soft and hard copies of the message and any attachments.  Thank you for your cooperation.
    ====================================================
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
    --------------------------------------------------------------------------
    

  • Next message: Matt Shelton: "Passive Asset Detection System v1.1.3 Released"

    Relevant Pages

    • Re: Win32forth.exe deleted by McAfee VirusScan Enterprise
      ... We too observed an objection from a virus detector during installation. ... If the developers are told of the false positives they should make ... one of those reports was about Win32Forth... ...
      (comp.lang.forth)
    • Re: [PATCH] update checkpatch.pl to version 0.10
      ... hiding mostly useful tests is a good thing. ... should matter a lot and the default configuration for a static code ... to remove the false positives from them. ... very low in those reports and it those which drive my development effort. ...
      (Linux-Kernel)
    • Re: [PATCH 00/10] Kernel memory leak detector 0.8
      ... On 11/07/06, Catalin Marinas wrote: ... > It's not a memleak? ... of reports from __alloc_skb, maybe they were false positives and the ...
      (Linux-Kernel)
    • Re: Reinstall XP
      ... it reports many false positives. ... It identifies something as spyware which is not spyware. ... Removing may cause ...
      (microsoft.public.windowsxp.basics)
    • Re: Snort Network Suppression
      ... If you still get a lot of false positives, ... traffic on the network. ... with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)