Bluehost.com Web Hosting $6.95

Re: Re: [Snort-users] How can I recognize Snort rules with high false positive rate?

This is a discussion on Re: Re: [Snort-users] How can I recognize Snort rules with high false positive rate? within the Snort forums, part of the System Security and Security Related category; > The goal of IDS tuning is to reduce FPs to an acceptable level, while > trying to avoid setting ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-19-2004
Ali Zand
 
Posts: n/a
Default Re: Re: [Snort-users] How can I recognize Snort rules with high false positive rate?

> The goal of IDS tuning is to reduce FPs to an acceptable level, while
> trying to avoid setting up your system for FNs. This doesn't mean that
> I believe that there are never FNs--it just means that an operator
> should do everything possible to try and prevent them.
>
> Taking the "I don't care about FNs" approach to tuning will usually
> result in the operator carelessly disabling features and attack classes
> in the name of getting rid of FPs, which will serve the immediate
> purpose, but will likely result in a lot of missed legitimate detects as
> well.
>
> And when it all comes down to it, it's easy to dismiss FPs at the
> analyst's console. That's cheap compared to 50 FNs that were missed
> because some entire attack class was slashed in the name or FP reduction.
>

I'm going to use Snort in combination with another IDS, and I want to
detect attacks which Snort supports but the IDS does not.
So considering :
1. having another IDS
2. having several FP messages on that IDS and having to process these
false messages
3. Very high false alerts will lessen analyst sensitivity, and he/she
will not care about them anymore.
I want to have just very accurate rules of Snort.
I'm trying just to strengthen my original IDS.

Thanks


-------------------------------------------------------
This SF.Net email is sponsored by The 2004 JavaOne(SM) Conference
Learn from the experts at JavaOne(SM), Sun's Worldwide Java Developer
Conference, June 28 - July 1 at the Moscone Center in San Francisco, CA
REGISTER AND SAVE! http://java.sun.com/javaone/sf Priority Code NWMGYKND
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 01:53 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0