Snort mailing list archives
Re: Tweaking false positives
From: Erek Adams <erek () theadamsfamily net>
Date: Fri, 21 Sep 2001 11:18:35 -0700 (PDT)
On Fri, 21 Sep 2001, kaidhai wrote:
I am receiving a large number of alerts from a specific machine (DNS) that exists in my own LAN and is trusted. I want the alerts for such machines (ie, all such false positives) to be reduced. Any answers to that? Thanks in advance.
Configure snort. :) Have a look in snort.conf. You'll see the following: # Define the addresses of DNS servers and other hosts # if you want to ignore portscan false alarms from them... var DNS_SERVERS $HOME_NET [...] # Use portscan-ignorehosts to ignore TCP SYN and UDP "scans" from # specific networks or hosts to reduce false alerts. It is typical # to see many false alerts from DNS servers so you may want to # add your DNS servers here. You can all multiple hosts/networks # in a whitespace-delimited list. # #preprocessor portscan-ignorehosts: $DNS_SERVERS Uncomment that line out and all should be fine. Hope that helps! ----- Erek Adams Nifty-Type-Guy TheAdamsFamily.Net _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Tweaking false positives kaidhai (Sep 21)
- Re: Tweaking false positives Erek Adams (Sep 21)