On Monday, September 10, 2012, dan (ddp) <[email protected]> wrote:
> On Sat, Sep 8, 2012 at 6:55 PM, carlopmart <[email protected]> wrote:
>> Hi all,
>>
>>  Recently, I have setup a custom decoder to decode OpenBSD packet filter
>> logs. All works ok, except when certain packet filter logs arrives to
ossec
>> manager (all of them about queries to ntp servers), like this one:
>>
>> Sep  8 22:17:42 homefw obsdfw: Sep 08 22:17:41.670216 rule 29/(match)
[uid
>> 0, pid 6803] pass out on em1: 172.17.35.2.46932 > 176.74.25.243.123: [udp
>> sum ok] v4 client strat 0 poll 0 prec 0 dist 0.000000 disp 0.000000 ref
>> (unspec)@0.000000000 orig 0.000000000 rec -0.000000000 xmt
>> +539699832.364563345 [tos 0x10] (ttl 64, id 64826, len 76, bad cksum 38!)
>>
>> Whit this type of log, rule 1002 is triggered:
>>
>> Sep  8 22:17:42 bombadil obsdfw: Sep 08 22:17:41.670216 rule 29/(match)
[uid
>> 0, pid 6803] pass out on em1: 172.17.35.2.46932 > 176.74.25.243.123: [udp
>> sum ok] v4 client strat 0 poll 0 prec 0 dist 0.000000 disp 0.000000 ref
>> (unspec)@0.000000000 orig 0.000000000 rec -0.000000000 xmt
>> +539699832.364563345 [tos 0x10] (ttl 64, id 64826, len 76, bad cksum 38!)
>>
>>
>> **Phase 1: Completed pre-decoding.
>>        full event: 'Sep  8 22:17:42 homefw obsdfw: Sep 08 22:17:41.670216
>> rule 29/(match) [uid 0, pid 6803] pass out on em1: 172.17.35.2.46932 >
>> 176.74.25.243.123: [udp sum ok] v4 client strat 0 poll 0 prec 0 dist
>> 0.000000 disp 0.000000 ref (unspec)@0.000000000 orig 0.000000000 rec
>> -0.000000000 xmt +539699832.364563345 [tos 0x10] (ttl 64, id 64826, len
76,
>> bad cksum 38!)'
>>        hostname: 'homefw'
>>        program_name: 'obsdfw'
>>        log: 'Sep 08 22:17:41.670216 rule 29/(match) [uid 0, pid 6803]
pass
>> out on em1: 172.17.35.2.46932 > 176.74.25.243.123: [udp sum ok] v4 client
>> strat 0 poll 0 prec 0 dist 0.000000 disp 0.000000 ref
(unspec)@0.000000000
>> orig 0.000000000 rec -0.000000000 xmt +539699832.364563345 [tos 0x10]
(ttl
>> 64, id 64826, len 76, bad cksum 38!)'
>>
>> **Phase 2: Completed decoding.
>>        decoder: 'custom-openbsd-pf'
>>        action: 'pass'
>>        extra_data: 'em1'
>>        srcip: '172.17.35.2'
>>        srcport: '46932'
>>        dstip: '176.74.25.243'
>>        dstport: '123'
>>        proto: 'udp'
>>
>> **Phase 3: Completed filtering (rules).
>>        Rule id: '1002'
>>        Level: '2'
>>        Description: 'Unknown problem somewhere in the system.'
>> **Alert to be generated.
>>
>> As I can see, rule 1002 is triggered because "bad" word appears in this
log
>> ... but this is not a "Unknown problem somewhere in the system.". It is a
>> false possitive.
>>
>>  Is it possible to disable rule 1002 only for this case??. For example,
whem
>> my cutom-openbsd-pf decoder is used, disable rule 1002 ...
>>
>> Thanks.
>>
>> --
>> CL Martinez
>> carlopmart {at} gmail {d0t} com
>
> Why not create a rule to filter this out?
>
> <rule id="STUFF" level="0">
>   <if_sid>1002</if_sid>
>   <decoded_as>custom-openbsd-pf</decoded_as>
>   <match>bad cksum</match>
>   <proto>udp</proto>
>   <dstport>123</dstport>
>   <description>Ignore this.</description>
> </rule>
>
> (This is totally untested, so I could have mistyped something or
> dstport may not be available, etc.)
>

Thanks dan but I need to catch this "alert" as good. It can not be
discarded.

Reply via email to