cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
797
Views
0
Helpful
2
Replies

Average Parameter Settings

rpmanning
Level 1
Level 1

What engine parameters would be acceptable to tune out false positives. I do understand that this is network specific, but was looking for other's averages.

SERVICE.SMB (6255)? I'm thinking HitCount= ~25

FLOOD.NET (UDP)? I'm thinking Rate=4900

FLOOD.NET (TCP)? Maybe Rate=400

2 Replies 2

jsivulka
Level 5
Level 5

Have a look at the document 'SAFE: A Security Blueprint for Enterprise Networks'. It will provide a few pointers that you will find helpful.

http://www.cisco.com/en/US/netsol/ns340/ns394/ns171/ns128/networking_solutions_white_paper09186a008009c8b6.shtml

Great idea. Thanks

Review Cisco Networking for a $25 gift card