I am referring to IDS called Snort. In Snort there is a file called alert, which holds chronological summary( a BIG one) of possible security problems. Do you think that all of these alerts correspond to real attack?
No, SNORT (and all IDS's) will have MANY "false possitives".
The job of a security analyst is to go thru the logs proactively (and regularly <G>) looking for anomalies that point to security events.
It takes some time to fine tune an IDS to ignore the false positives but not miss an actuall security event, but by going thru the logs and looking at what is being reported, you will begin to learn the difference and be in a better position to manage your IDS
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.