BO2K-UDP sig false positive

Unanswered Question
Nov 7th, 2007

I'm experiencing what I believe to be a false positive on the BO2K-UDP (4055) signature. As near as I can tell, it is getting triggered by Xbox consoles when they connect to the Xbox Live! service. I am currently running the S307 sig update. What is the best way to report this to get it fixed?

Thanks,

Zach

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
jsivulka Wed, 11/14/2007 - 10:33

Each signature has a section called Benign Trigger(s), you can use this to determine any false positives.In regards to IDS 5.0 modes refer to the following link:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dminter.htm

Other 5.0 documentation can be found at the link below:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/index.htm

cashqoo Tue, 12/25/2007 - 19:53

I have encountered the BO2K alarm, after investigations, it is IPsec VPN traffic which triggers it.

you can tune the signature using IPS IDM.

If you have MARS, you have the option to create a false positive rule for it.

rgds

cash

mherald Mon, 12/31/2007 - 17:42

I ran into this one too. After I looked at things, it is IPsec VPN traffic which triggered it. It was getting fired when traffic went to the outside interface of the PIX (not ASA). The PIX is also does remote user VPN traffic.

Mike

Actions

This Discussion