[Snort-users] Tweaking false positives

Erek Adams erek at ...577...
Fri Sep 21 11:19:01 EDT 2001


On Fri, 21 Sep 2001, kaidhai wrote:

> I am receiving a large number of alerts from a specific machine (DNS) that
> exists in my own LAN and is trusted.  I want the alerts for such machines
> (ie, all such false positives) to be reduced.  Any answers to that? Thanks
> in advance.

Configure snort.  :)  Have a look in snort.conf.  You'll see the following:

# Define the addresses of DNS servers and other hosts
# if you want to ignore portscan false alarms from them...

var DNS_SERVERS $HOME_NET

[...]

# Use portscan-ignorehosts to ignore TCP SYN and UDP "scans" from
# specific networks or hosts to reduce false alerts. It is typical
# to see many false alerts from DNS servers so you may want to
# add your DNS servers here. You can all multiple hosts/networks
# in a whitespace-delimited list.
#
#preprocessor portscan-ignorehosts: $DNS_SERVERS

Uncomment that line out and all should be fine.

Hope that helps!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net





More information about the Snort-users mailing list