[Snort-users] Reliability of signatures
wkitty42 at ...14940...
Fri Feb 4 19:53:34 EST 2011
On 2/4/2011 14:01, Matthew Jonkman wrote:
> I agree on the difference between just logging hits and having true FP and TP ratings. But even a false positive can be different on the same packet in different organizations. Many folks mark a hit a false positive because it's just not of interest, vs nt hitting on what it's supposed to be looking for.
agreed and that's quite incorrect... especially when the hit does exactly match
the rule(s) as written...
on sidreporter, i'm still trying to work out how to be able to participate in it
in an automated way in my environment... once this is done, it is possible that
several hundred thousand more participant may appear... but...
More information about the Snort-users