Advertisement

08.29.2007 at 11:49AM PDT, ID: 22795307
[x]
Attachment Details

Tuning Snort - http_inspect Preproccessor

Asked by seag33k in Intrusion Detection Systems (IDS), Linux, Miscellaneous Security

Tags: snort, http_inspect, tuning

I am trying to tune my new Snort box.  I am getting a number of false positive alerts related to the http_inspect preproccessor.  The alerts are associated with outgoing traffic from my users going to various websites and not incoming traffic to my webserver.  In addition, we are only allowing inbound SSL connections for our web mail.  These are the alerts that are being triggered:

http_inspect: BARE BYTE UNICODE ENCODING
http_inspect: DOUBLE DECODING ATTACK
http_inspect: IIS UNICODE CODEPOINT ENCODING


If I edit the snort.conf file with something like this:

preprocessor http_inspect_server: server default \
                        ports { 80 3128 } \
                        non_strict \
                        non_rfc_char { 0x00 } \
                        flow_depth 300 \
                        bare_byte no \
                        double_decode no \
                        iis_unicode no \
                     

Will this eliminate the alerts I am getting?  Also, will it impact the processing down the line for the rules I've enabled?  As I understand it, the http_inspect preproccessor also assists with the detection of rule violations enabled in the snort.conf file as well.  In general, I want to limit the numerous false positives I am getting, but not at the expense of somewhat crippling the effectiveness of the IDS.

Thanks!
Start Free Trial
 
 
[+][-]08.31.2007 at 12:05AM PDT, ID: 19806455

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Intrusion Detection Systems (IDS), Linux, Miscellaneous Security
Tags: snort, http_inspect, tuning
Sign Up Now!
Solution Provided By: pazwant
Participating Experts: 2
Solution Grade: A
 
 
[+][-]08.31.2007 at 08:14AM PDT, ID: 19808896

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 7-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]02.04.2008 at 06:16AM PST, ID: 20814417

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 7-day free trial to view this Administrative Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628