store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed May 22, 2013 5:31 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 
Author Message
 Post subject: Feature request: test event on new rules
Unread postPosted: Mon Jan 09, 2012 1:20 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
This is a really complicated feature to implement, but I wonder if it might be useful.

I needed to report a false positive today. To my surprise the GUI prevented it saying my rules weren't up to date. OK, fair enough. I *was* one step behind on my rules updates.

But here's where it went wrong:

I updated using asl -u then went back to the same event I had tried to report previously, and of course I was allowed to report the FP, even though the event had happened when I previous ruleset has been used.

What I'd like is a feature in the GUI that lets me test a previously logged event against the current ruleset.

By this I mean a button in the GUI that's visible when I've clicked on an event shown in event log in the GUI that allows me to see if that event would or would not trigger a mod_sec/ossec reaction with the ruleset currently loaded.

In this way, when I've reported an FP for an event in the past, I can test that exact same event against the new ruleset to know if that ruleset has fixed my FP or not.

But more importantly, having been gently rebuked by the GUI for attempting to report an FP when my rules were not up to date, I could update the rules and then use the same feature to test the event against the new rules - if I still get an indication that mod_sec or ossec would take action as a result of the event, I know it is sensible to report it as an FP. If not, then I know I'd be wasting everybody's time by reporting it as an FP.

This would only work for events where enough data is captured, e.g. an html post/get, of course. I can also see serious danger potential. For example, we don't want any possibility at all of a remote file inclusion or similar horrible thing accidentally working when doing a GUI-based event test like this.


[DARN IT. Sorry. Posted in the wrong section. I'm sure Mike/Scott will move this thread to the right place for me though :-) ]

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Feature request: test event on new rules
Unread postPosted: Mon Jan 09, 2012 3:16 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Wonderful idea, and dont worry about posting it here. Happens to the best of us. :-)

As you know, our developers are on a development retreat this week, and we'll brain storm on this one tomorrow. So great timing!

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group