[sniffer] FPs on Sniffer-Schemes

2012-03-12 Thread Darin Cox
Hi Pete,

We're seeing a ton of FPs on a Sniffer-Schemes rule # 4764784.

Darin.


[sniffer] Re: FPs on Sniffer-Schemes

2012-03-12 Thread Darin Cox
More info...

Started getting hits at 4:30pm EST up to 15 minutes ago (5:25pm EST).  Not sure 
if the rule has been pulled or corrected yet.

Had 383 hits, and a very high percentage of those were FPs.  Don't have an 
exact number, due to having to release the messages quickly for delivery, but I 
expect at least 30% were FPs for us.  Most were referencing PO #s or orders for 
various customers.

Darin.


- Original Message - 
From: Darin Cox 
To: Message Sniffer Community 
Sent: Monday, March 12, 2012 5:17 PM
Subject: [sniffer] FPs on Sniffer-Schemes


Hi Pete,

We're seeing a ton of FPs on a Sniffer-Schemes rule # 4764784.

Darin.


[sniffer] Re: FPs on Sniffer-Schemes

2012-03-12 Thread Pete McNeil

  
  
On 3/12/2012 5:17 PM, Darin Cox wrote:

  
  
  
  Hi Pete,
  
  We're seeing a ton of FPs on a
  Sniffer-Schemes rule # 4764784.


That rule was detected as an error and removed almost immediately
after it was created.
You should not be seeing any additional hits on that rule.

Best,

_M


-- 
Pete McNeil
Chief Scientist
ARM Research Labs, LLC
www.armresearch.com
866-770-1044 x7010
twitter/codedweller 

  

#

This message is sent to you because you are subscribed to

  the mailing list sniffer@sortmonster.com.

This list is for discussing Message Sniffer,

Anti-spam, Anti-Malware, and related email topics.

For More information see http://www.armresearch.com

To unsubscribe, E-mail to: sniffer-...@sortmonster.com

To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com

To switch to the INDEX mode, E-mail to sniffer-in...@sortmonster.com

Send administrative queries to  sniffer-requ...@sortmonster.com




[sniffer] Re: FPs on Sniffer-Schemes

2012-03-12 Thread Pete McNeil

  
  
On 3/12/2012 5:41 PM, Darin Cox wrote:
Started getting hits at 4:30pm EST up to
15 minutes ago (5:25pm EST). Not sure if the rule has been
pulled or corrected yet.
It was corrected nearly as soon as it was created. It did escape
into some rulebases - we saw that on our conflict instrument. Most
systems auto-panicked the rule right away. It no longer appears on
our conflict instruments - so there is no reason you should see any
hits from it.

I'm chasing things down to see what I can see -- based on your
message.

Best,

_M

-- 
Pete McNeil
Chief Scientist
ARM Research Labs, LLC
www.armresearch.com
866-770-1044 x7010
twitter/codedweller 

  

#

This message is sent to you because you are subscribed to

  the mailing list sniffer@sortmonster.com.

This list is for discussing Message Sniffer,

Anti-spam, Anti-Malware, and related email topics.

For More information see http://www.armresearch.com

To unsubscribe, E-mail to: sniffer-...@sortmonster.com

To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com

To switch to the INDEX mode, E-mail to sniffer-in...@sortmonster.com

Send administrative queries to  sniffer-requ...@sortmonster.com




[sniffer] Re: FPs on Sniffer-Schemes

2012-03-12 Thread Pete McNeil

  
  
On 3/12/2012 5:41 PM, Darin Cox wrote:
Started getting hits at 4:30pm EST up to
15 minutes ago (5:25pm EST).
I think I can see part of the problem (possibly).
I do not have telemetry from your system (based on looking up your
Id from your domain). I suspect this means that you are running an
older version of SNF. By extension, that would mean a couple of
things:

* Your rulebase update would not come as quickly as for most
systems.
* Your SNF engine won't match on many of the newer rules.
* Your SNF engine will not have GBUdb and also will not be able to
auto-panic new rules that conflict with IP reputation data.

Am I right about these assumptions?
If not, then we should figure out why I don't see your telemetry.

Thanks,

_M

-- 
Pete McNeil
Chief Scientist
ARM Research Labs, LLC
www.armresearch.com
866-770-1044 x7010
twitter/codedweller 

  

#

This message is sent to you because you are subscribed to

  the mailing list sniffer@sortmonster.com.

This list is for discussing Message Sniffer,

Anti-spam, Anti-Malware, and related email topics.

For More information see http://www.armresearch.com

To unsubscribe, E-mail to: sniffer-...@sortmonster.com

To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com

To switch to the INDEX mode, E-mail to sniffer-in...@sortmonster.com

Send administrative queries to  sniffer-requ...@sortmonster.com