Snort mailing list archives

Re: Reliability of signatures


From: waldo kitty <wkitty42 () windstream net>
Date: Fri, 04 Feb 2011 19:53:34 -0500

On 2/4/2011 14:01, Matthew Jonkman wrote:
I agree on the difference between just logging hits and having true FP and TP ratings. But even a false positive can 
be different on the same packet in different organizations. Many folks mark a hit a false positive because it's just 
not of interest, vs nt hitting on what it's supposed to be looking for.

agreed and that's quite incorrect... especially when the hit does exactly match 
the rule(s) as written...

on sidreporter, i'm still trying to work out how to be able to participate in it 
in an automated way in my environment... once this is done, it is possible that 
several hundred thousand more participant may appear... but...

------------------------------------------------------------------------------
The modern datacenter depends on network connectivity to access resources
and provide services. The best practices for maximizing a physical server's
connectivity to a physical network are well understood - see how these
rules translate into the virtual world? 
http://p.sf.net/sfu/oracle-sfdevnlfb
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: