[Snort-sigs] SID: 2189 False Positive
hsantos at ...2196...
Mon Feb 2 06:43:10 EST 2004
# This is a template for submitting snort signature descriptions to
# the snort.org website
# Ensure that your descriptions are your own
# and not the work of others. References in the rules themselves
# should be used for linking to other's work.
# If you are unsure of some part of a rule, use that as a commentary
# and someone else perhaps will be able to fix it.
Summary: This event is generated when a suspicious packet using an unusual
protocol is sent to a router.
Ease of Attack:
False Positives: When using multicast we noted several false positives from
the LAN router, using the multicast addresses, towards several host in the
Contributors: Henrique Santos (hsantos at ...2196...)
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-sigs