BO2K-UDP sig false positive

Unanswered Question
Nov 7th, 2007
User Badges:

I'm experiencing what I believe to be a false positive on the BO2K-UDP (4055) signature. As near as I can tell, it is getting triggered by Xbox consoles when they connect to the Xbox Live! service. I am currently running the S307 sig update. What is the best way to report this to get it fixed?


Thanks,


Zach

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
jsivulka Wed, 11/14/2007 - 10:33
User Badges:
  • Bronze, 100 points or more

Each signature has a section called Benign Trigger(s), you can use this to determine any false positives.In regards to IDS 5.0 modes refer to the following link:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dminter.htm

Other 5.0 documentation can be found at the link below:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/index.htm


cashqoo Tue, 12/25/2007 - 19:53
User Badges:

I have encountered the BO2K alarm, after investigations, it is IPsec VPN traffic which triggers it.


you can tune the signature using IPS IDM.

If you have MARS, you have the option to create a false positive rule for it.


rgds

cash

mherald Mon, 12/31/2007 - 17:42
User Badges:

I ran into this one too. After I looked at things, it is IPsec VPN traffic which triggered it. It was getting fired when traffic went to the outside interface of the PIX (not ASA). The PIX is also does remote user VPN traffic.


Mike

Actions

This Discussion