Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Handle of flipped Zeek flows #41

Open
verovaleros opened this issue Oct 25, 2024 · 0 comments
Open

Handle of flipped Zeek flows #41

verovaleros opened this issue Oct 25, 2024 · 0 comments

Comments

@verovaleros
Copy link
Member

One of the suspected sources of possible FP is how AIP may be treating the flipped zeek flows. See, for example https://community.zeek.org/t/caret-and-the-stick/5012.

This would somehow make a connection going on to say, Google, appearing in the Zeek logs as an attack.

The flow was flipped by Zeek's heuristic, which we trust is as good as it can get. However, maybe some additional checks can be done to process these type of flows differently to achieve higher accuracy.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: 🆕 New
Development

No branches or pull requests

1 participant