Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata STREAM alerts

    Scheduled Pinned Locked Moved IDS/IPS
    3 Posts 3 Posters 9.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      swmspam
      last edited by

      I'm getting a lot of SURICATA STREAM alerts. These are related to the stream-events.rules file. Looking through the alert logs, I see iOS devices are primarily responsible, particularly iPhones (more so than iPads).

      I was disabling the rules one-by-one as they occurred but they keep coming. So I put into disabledsid.conf:

      1:2210000-1:2219999

      This disables the entire TCP stream engine rules.

      • Is there something valuable in the TCP stream engine rules that I should be concerned about keeping?

      • Anyone else seeing this behavior?

      1 Reply Last reply Reply Quote 0
      • P
        pfBasic Banned
        last edited by

        you can just disable the whole category, there are plenty of posts on here suggesting exactly that.

        1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by

          An IDS/IPS assumes that all applications (and thus software developers) follow all the standards for networking, so when the IDS/IPS sees something that looks amiss it will alert on it.  Unfortunately that assumption about all applications (and developers) solidly adhering to all published networking standards is a pipe dream… ;)

          The downside for IT Security Admins is we get flooded with spurious alerts that we have to spend time investigating.  The STREAM alerts are about as worthless in Suricata as the HTTP_INSPECT alerts in Snort.  What I mean by that blanket statement is there are so many false positives from both of those that they are both nearly worthless.  Most IT Security Admins will disable the majority, if not all, of these rules.

          Bill

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.