Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » Alert Analisys

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Alert Analisys


Posted by francescoflora on June 07, 2005 00:21:37

Hi guys,
Analyzing alerts I've foun lot of traffic from different stations marked as (portscan) TCP Portsweep.
What could it be?
Thanks

Posted by bfranklin on June 07, 2005 08:33:39

Could be a lot of stuff. Can you post the port numbers that are being hit?

Posted by Apachez on June 09, 2005 05:46:26

As I have found its mostly false alerts, or at least not as "critical" as they can look at the first glanze.

I had a bittorrent client running one night last week with snort running on the same machine with all certified rules enabled and ended up with a "proto255" (portscan log) that was 2 gig large (all other logs for each ip was like a few kilobytes).