|
Re: Thresholds on Policy Rules: msg#00129security.ids.snort.sigs
Jason wrote:
Yes, but there are far too many real sources I think. Maybe we should consider then the idea of having one static word that is one prone to falses (lesbian, masturbation, anal, virgin, etc) and have a pcre in the same rule to make sure there's a more vulgar word in there. The anchor word would be the iffy factor and the vulgar one the more concrete that tells us this is pron and not virginia. I don't think it'd be too processor intensive a pcre statement. Here are some thoughts based on my past experience with this problem.That's what we ought to do, I agree. We're only intending to get the huge violators, these will show withing that. 2) Look for cookies, sextracker is pretty common and sure to catch the actual valid porn surfer. That's a good idea. How so? Ya, I agree that that's a better way. But not always feasible.
I think we're approaching a religious argument there. :)
Valid points. And if Brian and crew think that's the case I wouldn't really argue that much. It's one of those things that draw us as security folks out of our element and make us use our toys for other things that dilute the value. And besides, if they come out of the snort rules they'd have a welcome home at bleedingsnort. As would any wayward orphaned rule. :) Thanks for the points Jason. You almost have me talked out of it. :) Matt ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Signature Proposal: 00129, Holger Heimann |
|---|---|
| Next by Date: | Re: Bleeding-Edge Porn: 00129, Matt Jonkman |
| Previous by Thread: | Re: Thresholds on Policy Rulesi: 00129, Jason |
| Next by Thread: | Re: Thresholds on Policy Rules: 00129, James Riden |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |