<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Botnet Filter Hits - Reliability? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250663#M348693</link>
    <description>&lt;P&gt;We just licensed one of our ASAs at a branch office with the botnet filter license and I'm already seeing some hits in the ASDM.&amp;nbsp; My question is really about the reliability of the results.&amp;nbsp; I know with the IPS sensors, it's pretty common to get false positives so I want to be careful with how I treat the results on hits for botnet activity.&amp;nbsp; We've run a few different virus scans on the computers that are supposedly reaching out to malicious sites, but they haven't returned anything malicious being on the PC.&amp;nbsp; I don't want to dismiss these, but before we start spending time really investigating the computers and disrupting the users I want to get a feel for percentage of reliability on the botnet filters alone.&amp;nbsp; Any thoughts or experiences anybody can share? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this posts answers your question or is helpful, please consider rating it and/or marking as answered.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:52:42 GMT</pubDate>
    <dc:creator>Christopher Bell</dc:creator>
    <dc:date>2019-03-12T01:52:42Z</dc:date>
    <item>
      <title>Botnet Filter Hits - Reliability?</title>
      <link>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250663#M348693</link>
      <description>&lt;P&gt;We just licensed one of our ASAs at a branch office with the botnet filter license and I'm already seeing some hits in the ASDM.&amp;nbsp; My question is really about the reliability of the results.&amp;nbsp; I know with the IPS sensors, it's pretty common to get false positives so I want to be careful with how I treat the results on hits for botnet activity.&amp;nbsp; We've run a few different virus scans on the computers that are supposedly reaching out to malicious sites, but they haven't returned anything malicious being on the PC.&amp;nbsp; I don't want to dismiss these, but before we start spending time really investigating the computers and disrupting the users I want to get a feel for percentage of reliability on the botnet filters alone.&amp;nbsp; Any thoughts or experiences anybody can share? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this posts answers your question or is helpful, please consider rating it and/or marking as answered.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250663#M348693</guid>
      <dc:creator>Christopher Bell</dc:creator>
      <dc:date>2019-03-12T01:52:42Z</dc:date>
    </item>
    <item>
      <title>Botnet Filter Hits - Reliability?</title>
      <link>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250664#M348694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Christopher,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you are doing fine, I can see that you have the kwnoledge to run a botnet filter on the ASA so your question goes to how the botnet filter behaves, where it takes the domain.names from blacklisted sites and how accurate it is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well the botnet feature on the ASA will work by inspecting all sessions from in-out and out-in by checking if the domain name of the site you are attempting to connect is known as problematic or not, So it's a dynamic database and that is the keyword.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so what's being blocked today may be allowed on the next weeks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a number of sensors (internal and external) which provide details about different sites and we combine all details, do our internal analysis (both manual and automatic) before marking a site as malware. Also keep in mind that the reputation of site is dynamic and it could change every time when someone visits the site, so it may host malware this minute or hour and maybe the next minute or hour it may be valid as I already mentioned before.&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #666666; font-family: Arial; font-size: 12px; line-height: 15px; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Here are a few (not all) web-sites that we refer to:&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #666666; font-family: Arial; font-size: 12px; line-height: 15px; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Senderbase.org&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.senderbase.org/senderbase_queries/rep_l"&gt;http://www.senderbase.org/senderbase_queries/rep_l&lt;/A&gt;&lt;/P&gt;&lt;P&gt;ookup&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #666666; font-family: Arial; font-size: 12px; line-height: 15px; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;MyWot - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.mywot.com/en/scorecard/example.com"&gt;http://www.mywot.com/en/scorecard/example.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #666666; font-family: Arial; font-size: 12px; line-height: 15px; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Google Safe browsing&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.google.com/safebrowsing/diagnostic?site"&gt;http://www.google.com/safebrowsing/diagnostic?site&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt;=xxxxxx.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jun 2013 22:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250664#M348694</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-03T22:09:53Z</dc:date>
    </item>
    <item>
      <title>Botnet Filter Hits - Reliability?</title>
      <link>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250665#M348697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; To clarify, the filter engine then is inspecting packets sourced/destined to known sites hosting malicious software - not just botnet command and control type servers.&amp;nbsp; So 'hits' on the filter engine don't necessarily indicate that a client is infected with malicious software, only that it is visiting a site with a reputation of currently hosting malicious software.&amp;nbsp; Does that sound correct?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this posts answers your question or is helpful, please consider rating it and/or marking as answered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 12:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250665#M348697</guid>
      <dc:creator>Christopher Bell</dc:creator>
      <dc:date>2013-06-04T12:42:58Z</dc:date>
    </item>
    <item>
      <title>Botnet Filter Hits - Reliability?</title>
      <link>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250666#M348700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Christopher,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exactly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally a botnet infected host will present the behavior that this particular feature will prevent(going to known malicious sites) but it will prevent the user going to this malicious sites before even infected as well,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A win, win, wherever you see it &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You got it know,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Remember to rate all of the helpful posts &lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 14:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250666#M348700</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-04T14:48:14Z</dc:date>
    </item>
    <item>
      <title>Botnet Filter Hits - Reliability?</title>
      <link>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250667#M348701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been using botnet filtering for the previous 5 months.&amp;nbsp; We have noticed a decrease in desktop/laptop infections. There have been a couple of instances where outside organizations have tried to access my infrastructure. Their access attempts were blocked. Each instance, the outside organization had a virus outbreak.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One item that I am not clear on is how to get off the black list.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 17:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250667#M348701</guid>
      <dc:creator>rmeans</dc:creator>
      <dc:date>2013-06-04T17:39:41Z</dc:date>
    </item>
    <item>
      <title>Botnet Filter Hits - Reliability?</title>
      <link>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250668#M348702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rmeans,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically there is no manual way to get off of the black list as this would mean a vulnerability.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check if there is a blacklisted domain on the following site:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #666666; font-family: Arial; font-size: 12px; line-height: 15px; background-color: #ffffff;"&gt;Here are a few (not all) web-sites that we refer to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Senderbase.org&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.senderbase.org/senderbase_queries/rep_lookup"&gt;http://www.senderbase.org/senderbase_queries/rep_lookup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MyWot - &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.mywot.com/en/scorecard/example.com"&gt;http://www.mywot.com/en/scorecard/example.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Google Safe browsing&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.google.com/safebrowsing/diagnostic?site=xxxxxx.com"&gt;http://www.google.com/safebrowsing/diagnostic?site=xxxxxx.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are not all,just some&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to report a false positive you will need to send an email specifying the reason of that :&lt;/P&gt;&lt;P style="color: #666666; font-family: Arial; font-size: 12px; line-height: 15px; background-color: #ffffff;"&gt;&lt;SPAN&gt; Send an e-mail to "&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:btf-l4tm-escalations@cisco.com"&gt;btf-l4tm-escalations@cisco.com&lt;/A&gt;&lt;SPAN&gt;" and cc:&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:email-in@cisco.com"&gt;email-in@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;Remember to rate all of the helpful posts&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 19:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250668#M348702</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-04T19:20:39Z</dc:date>
    </item>
    <item>
      <title>Botnet Filter Hits - Reliability?</title>
      <link>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250669#M348703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The email address you provided does not seem to be working to report possible false positives.&amp;nbsp; Can you double check that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this posts answers your question or is helpful, please consider rating it and/or marking as answered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 18:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250669#M348703</guid>
      <dc:creator>Christopher Bell</dc:creator>
      <dc:date>2013-06-13T18:46:38Z</dc:date>
    </item>
    <item>
      <title>Botnet Filter Hits - Reliability?</title>
      <link>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250670#M348704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Christopher,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's possible that only via TAC u could report that but before confirming that can you try this:&lt;/P&gt;&lt;PRE style="margin: 0px 10px 10px; padding: 5px; background-color: #e5e5e5; border: 1px dotted #808080; overflow-x: scroll; white-space: pre-wrap; color: #666666; font-size: 12px; line-height: 15px;"&gt;support@senderbase.org&lt;/PRE&gt;&lt;P&gt; Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts. &lt;BR /&gt; &lt;BR /&gt;For this community that's as important as a thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 20:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-filter-hits-reliability/m-p/2250670#M348704</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-06-13T20:07:25Z</dc:date>
    </item>
  </channel>
</rss>

