<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5894:1 Storm Worm in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834540#M85641</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This signature is designed to detect the botnet behavior of an infected machine.  Some possible options are to exclude your DNS servers as a source or destination, or you could modify the ports to ignore 53 (1-51,54-65535).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Sep 2007 13:38:05 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2007-09-27T13:38:05Z</dc:date>
    <item>
      <title>5894:1 Storm Worm</title>
      <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834539#M85640</link>
      <description>&lt;P&gt;The signature generates false positives on DNS traffic.&lt;/P&gt;&lt;P&gt;An example is a DNS query with an Transaction ID: 0xE30F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At networks with a lot of DNS traffic the signature will produces 30+ alarms per day.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834539#M85640</guid>
      <dc:creator>m-hansson</dc:creator>
      <dc:date>2019-03-10T10:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: 5894:1 Storm Worm</title>
      <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834540#M85641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This signature is designed to detect the botnet behavior of an infected machine.  Some possible options are to exclude your DNS servers as a source or destination, or you could modify the ports to ignore 53 (1-51,54-65535).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2007 13:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834540#M85641</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-09-27T13:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: 5894:1 Storm Worm</title>
      <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834541#M85642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it just me or lately the quality the signatures out of the box is less than satisfactory?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2007 15:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834541#M85642</guid>
      <dc:creator>apolkosnik</dc:creator>
      <dc:date>2007-10-03T15:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: 5894:1 Storm Worm</title>
      <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834542#M85643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about modifying the signature so it wont look at the transaction ID for DNS traffic? - A lot better than having everyone with a Cisco IDS/IPS sensor to add filters or change the ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes I agree, signature quality is sometimes really poor. This is a good example.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2007 09:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834542#M85643</guid>
      <dc:creator>m-hansson</dc:creator>
      <dc:date>2007-10-04T09:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: 5894:1 Storm Worm</title>
      <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834543#M85644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most people just don't want to be bothered with tweaking. If it's too noisy, it gets disabled.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2007 12:29:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834543#M85644</guid>
      <dc:creator>apolkosnik</dc:creator>
      <dc:date>2007-10-04T12:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: 5894:1 Storm Worm</title>
      <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834544#M85645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might consider having generic filters for your DNS servers anyway.  It is not uncommon for traffic to/from them to trigger a variety of signatures. Trying to create a regex that matches one thing but not another is sometimes very difficult. In our own environment, the botnet behavior would likely be very noticeable for other reasons, so the signature may not be the useful anyway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2007 13:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834544#M85645</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-10-04T13:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: 5894:1 Storm Worm</title>
      <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834545#M85646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ehh? So just because there already are a lot of bad quality signatures we should accept more?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess the current engines can't handle this type of advanced signatures and that's too bad. Several competitors are making way more advanced signatures.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2007 13:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834545#M85646</guid>
      <dc:creator>m-hansson</dc:creator>
      <dc:date>2007-10-25T13:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: 5894:1 Storm Worm</title>
      <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834546#M85647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, you shouldn't, especially if you believe there is greener pasture available;-)  You could open a ticket with Cisco to fix if you think it's possible to create a "tighter" signature.  Until then, I would suggest filtering.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2007 13:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834546#M85647</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-10-29T13:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: 5894:1 Storm Worm</title>
      <link>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834547#M85648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I actually posted this before I saw this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=General&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cbe5171" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=General&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cbe5171&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seeing this fire falsely for an entirely different reason, for nginx servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone successfully tightened up this signature?  If so, can you let me know how?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2007 19:37:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5894-1-storm-worm/m-p/834547#M85648</guid>
      <dc:creator>nykoelle01</dc:creator>
      <dc:date>2007-10-29T19:37:55Z</dc:date>
    </item>
  </channel>
</rss>

