Snort mailing list archives

Re: Tweaking false positives


From: Erek Adams <erek () theadamsfamily net>
Date: Fri, 21 Sep 2001 11:18:35 -0700 (PDT)

On Fri, 21 Sep 2001, kaidhai wrote:

I am receiving a large number of alerts from a specific machine (DNS) that
exists in my own LAN and is trusted.  I want the alerts for such machines
(ie, all such false positives) to be reduced.  Any answers to that? Thanks
in advance.

Configure snort.  :)  Have a look in snort.conf.  You'll see the following:

# Define the addresses of DNS servers and other hosts
# if you want to ignore portscan false alarms from them...

var DNS_SERVERS $HOME_NET

[...]

# Use portscan-ignorehosts to ignore TCP SYN and UDP "scans" from
# specific networks or hosts to reduce false alerts. It is typical
# to see many false alerts from DNS servers so you may want to
# add your DNS servers here. You can all multiple hosts/networks
# in a whitespace-delimited list.
#
#preprocessor portscan-ignorehosts: $DNS_SERVERS

Uncomment that line out and all should be fine.

Hope that helps!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: