Seems to me that there is also an interpretation that, once the rule has fired and six more firings have occurred, there will be a frequency alert for each subsequent firing until the events per time interval is no longer operative. I realize that most "frequency warning systems" don't do this but instead reset to zero after each event/interval firing has occurred.
I have problems with the nomenclature for this: the word "frequency" really (in the real world) means some number of events per unit of time, but in the OSSEC rule definition it really means more like "count", and "timeframe" really means "interval". This confused me for a fair while at first until I saw some examples and read their explanations. I think that changing these to "count" and "interval", instead of "frequency" and "timeframe", would go a long way to improving understanding of this kind of rule. -- Shane Castle Data Security Mgr, Boulder County IT CISSP GSEC GCIH -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of --[ UxBoD ]-- Sent: Thursday, February 10, 2011 13:11 To: [email protected] Subject: Re: [ossec-list] Overriding a rule ----- Original Message ----- > Hey, > > The frequency of 6, actually means 8 events for it to alert. It makes > sense when you think of the rule in these terms: > > if_matched_sid -> Alert me if the rule XYZ fired in the last ABC > seconds more than 6 times (not including the current event). > > So in your case, the rule 5551 will check if in the last few minutes > the rule 5503 was set more than 6 times... So out of the 31 > events, you would get 3 alerts from the rule 5551. > > So why is that? Because you can write rules like this one: > > <if_group>authentication_success</if_group> > <if_matched_group>authentication_failure</if_matched_group> > > So the current event is not tied to the list when searching on the > if_matched_* signatures.... > > Hope it made some sense :) > > Thanks, > Hi Daniel, Thank you very much for taking the time to respond it is appreciated. Would it not be 7 events then ? If 6 had come through, and one discards the current, then you would be alerting on the seventh. Long day so trying to get my head around the logic :) Thanks, P.
