Snort mailing list archives

Re: Outdated rules


From: wkitty42 () windstream net
Date: Mon, 28 Aug 2017 10:29:56 -0400

On 08/24/2017 10:37 AM, Frank Beer via Snort-sigs wrote:
Dear Snort-Team,

as new Snort user, I recently had a discussion with colleagues about the roll-out process of rules in Snort without clear result. Therefore I'm
writing you hoping for concrete answers: Suppose we have an active Snort rule
in place covering a reported exploit. What happens with the rule in upcoming
rule set releases if it is quite certain that the exploit cannot reoccur
again for some reason (e.g. the exploit simply was fixed or system
environment where the exploit can take action becomes obsolete)? I'm asking
that, because we are afraid of potential false alarms caused by such rules in
our system environment?

your team should always be monitoring... if a lot of FPs start happening, they should look to see why they are happening... if they are true FPs and the rule is no longer needed, then you disable the rule and move on... if there are still some TPs, then you would only disable the rule for certain IPs (see threshold.conf)...

tuning an IDS/IPS is an ongoing process... there is no "one size fits all" scenario... system updates can easily change your network's traffic necessitating a change in IDS/IPS configurations...


--
 NOTE: No off-list assistance is given without prior approval.
       *Please keep mailing list traffic on the list unless*
       *a signed and pre-paid contract is in effect with us.*
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

http://www.snort.org

Please visit http://blog.snort.org for the latest news about Snort!

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" 
https://snort.org/downloads/#rule-downloads";>emerging threats</a>!


Current thread: