01-10-2005 07:18 AM - edited 03-10-2019 01:13 AM
What engine parameters would be acceptable to tune out false positives. I do understand that this is network specific, but was looking for other's averages.
SERVICE.SMB (6255)? I'm thinking HitCount= ~25
FLOOD.NET (UDP)? I'm thinking Rate=4900
FLOOD.NET (TCP)? Maybe Rate=400
01-13-2005 02:10 PM
Have a look at the document 'SAFE: A Security Blueprint for Enterprise Networks'. It will provide a few pointers that you will find helpful.
01-21-2005 12:17 PM
Great idea. Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide