Here's my $0.02:

It can be very difficult to tell what those large packets actually are, because
one has to know the larger context in which they are being sent in order to make
a decision.  For instance, I see this sort of alert frequently -- with packet
captures which contain the same gibberish as do yours -- when one of our local
users starts up an on-line "radio" and starts listening to music.  I also get
lots of icmp type-8 packets which trip the alert, but these contain all zeros.
None of these appear to be an attack in any form.

In my experience, the "large packet" rules give lots of false positives; so,
unless you're getting flooded with these and the nature of the source and target
machines don't make sense ( e.g.: on-line music site/student known to you ),
then I expect these alerts are not significant.

