Signature 1315 - ACK w/o TCP Stream - why alerting?

We upgraded one of our sensors to 6.0(1)E1 and now we are seeing extremely high alerts on this particular signature. The signature is NOT set to alert. Any ideas on what we can do to stop the alert other than filter something that should not need filtering?
Thanks,

Do you have an event action override installed on the system to generate an alert for a risk rating (RR) greater than some value? If so, then even signatures that are set to "no action" will get the override applied if their resultant RR satifies the override criteria.
If this is the case, then you have several options...you can adjust the override to raise the minimum RR value that triggers the override, or, you can tune the signature to lower its effect RR. The later can be accomplished by lowering either its Severity level (info, low, medium, high etc) or lowering its Fidelity value.
The signature helps address some covert channels used by some exploit software.

Similar Messages

  • TCP Stream Reconstruction

    Hi,
    I'm working on a project based on the PCAP library on the Windows platform (ie, using WinPCap). I need a method (an algorithm, rather) to reconstruct TCP streams based on captured packets.
    A spoon-fed library to do the job for me would be most appreciated! Does any such library exist? If not, how do I go about reconstructing TCP streams, primarily to decode HTTP/1.1 headers?
    Thanks,
    Sayan.

    TCP does not lose data. Show us the code that reads from the socket.

  • Monitor a TCP port but alert only if timed out X times

    Hello,
    I need to build a moniotr that will probe a TCP port but alert only if timed out X times
    I was looking at Microsoft.SystemCenter.SyntheticTransactions.TCPPortCheckProbe module but it doesn't have this options
    Thanks,
    Marius

         You can check 
       http://www.ghacks.net/2010/05/25/tcp-port-monitor-port-alert/
         for TCP Port Monitor Port Alert

  • TCP STREAMING ISSUE? Please help

    HI 
    Iam posting here as my last resort to see if one of the many experts can resolve the anomaly I have on my BT Infinity option 2 totally unlimted package.
    The issue is streaming my slingbox a device which in the past has been sold in the BT shop .The slingbox is located abroad and  I have had BT infinity a few years now.
    when I first changed to  BT I first had this problem connecting to the slingbox ,it used to buffers slightly  and the onscreen application give stats on the streaming speed which when streaming,The stats would show the speed to be going at 2.5meg speed and then have sudden drops to 1meg which interupted viewing now this did not happen all the time but was intermittent. At this point it is very relevent to point out all other appliations have  worked without any noticble issues.
    Iam bringing this issue foward now because I have recently changed my work/shift patterns so I have weekends off and find myself at home on more evenings and therefore using this device more now from my Home broadband connection what I have noticed is that at he times Iam home the device not only has sudden drops but also struggles with the streaming speed 900kbps like there is restrictions on the type of data.
    When I do the bt wholesale speed test my stats are Brilliant 73meg down      16meg up on further diagnostics the line ip profile is 75 meg and it all looks good.
    However my BT infinity struggles with this application and struggles with streaming tcp on my slingbox which only needs 2.5meg to work flawlessly.
    I have regulary connected to my slingbox through different ISP be it  where I worked {BE BROADBAND} .my freinds house {sky fibre optic} and my brothers house who is on adsl2 with o2 broadband and he still is and has not changed quite yet to the sky infestrucure because he requires static ip. At these premises the slingbox streaming works faultlessly.
    That proves at least one thing that the problem does not reside at the source end.
    So over the last month or so that has led me to investigate my connection and what could be the possible causes of this problem being with my connection only.
    I have changed over from my BT router to top of the range LINKSYS 6700 changed wifi channels switched off wifi , connected 3 different laptops /pc via ethernet, disconnected all other devices etc and connected 1 PC at  a time had a new connection to my DP pole 14 months ago aswell as new internal wireing done by openreach. And the problems still persists more so at the evening and weekends.
    The last thing I tried was Wireshark which gives information on whatever data is going through the system. I  ran the application on my brothers connection using slingbox and under the heading PROTOCOL it shows as TCP.
    When i use wireshark at my connection under the same heading PROTOCOL its says HTTP and it says under the heading  INFO continuation or non HTTP traffic.
     I understand there maybe many under lining factors to why the application does not perform to the desired quality distance from cab , line etc but the reality is the device performs as it should do everywhere i have tried and my brothers who lives a few streets away laughs at me that he is on adsl connection and pays half the cost for his broadband but has alll his services working without issues. 
    I have rang BT technical a few times and although the BT tech team have tried to help I have gone round in circles in basically restarting router or modem.
    I do feel that maybe some sort of settings change from BT side will resolve this
    My contract is due to end with BT at the end of March 2014 and with regret if this issue is not corrected then unfortunetly I will have to change ISP provider.
    Thanks

    Hi I followed tha link to GLASHOST and when you try to test it comes back that there has been a error ?
    Is there another website I could try?
    Also how do I contact the MODS, regardless to the website not allowing me to test, at certain times (evening) there is definately throttling occuring or some setting on my line is causing this issue ,Iam sorry but tried to phone the TECH team but apart from power down modem or router there has been no effort made to try and resolve the problem.
    I need some one at BT with expert experiance and Know how to look into this thoroughly.
    I phoned customer options team yesterday and requested my MAC as I have less thn 1 month contract remaining,however  I  do not want to leave BT its a repitable company that has been trading for many years and its time that they showed that to me. do they care if I LEAVE?

  • TCP Programming / Why do not need to worry about Big and little Endian?

    Please help, I do not understand this concept please explain.
    The architecture of a CPU is either little-endian or big-endian; some modern CPU's allow a choice via software.
    The TCP/IP protocol standard specifies that all the bytes that make up an item must be sent in "network order", which happends to be big-endian. Intel Pentium CPU's are little-endian.
    This implies that on an Intel machine the TCP software will have to chop an int into bytes and then reverse the bytes before transmitting them.
    Why does the JAVA TCP software does not need to perform the reversal?
    Thanks,
    Alex

    But why would I need to use the DataOutputStream,You don't have to.
    But that's what the Java API provides for sending java primitives over a stream. You wouldn't have to use that. You could chop the int into bytes yourself, and send the bytes, and your Java code still wouldn't have to worry about the endiannes of it, because the VMs handle that.
    DataOutputStream just does the chopping and reassembling for you, so it's easier than doing it yoursefl.

  • My a/c name comes up on a shared photo stream, why?

    Hi I set up a photostream in my business name to show some clients my work and I always use a pseudonym to keep my ID private as I have a nasty ex that was tracking me, when I posted the photostream to my clients it was the new beta stream and had my account name/real name all over it. I thought it would just have the photo stream name. Is there an option so you can put pseudonyms instead of your full name?
    I don't have my name on any other photo apps so why are Apple deciding that emblazoning it everywhere is a good idea?

    That's good to know. I have wondered how that is done.
    You sir are indeed the Captain.
    !http://img41.imageshack.us/img41/2006/captaineq.jpg!

  • How can I know the end of TCP stream and/or SOAP over HTTP flow

    Hi all!
    I want to read SOAP messages over HTTP, from sniffed TCP fragments.
    How can I decide that the TCP and/or the HTTP fragmenst finished?
    For example there is a SOAP message sliced to 5 TCP packets, and the first packet contains the HTTP header and some SOAP content too. The last packet contains the SOAP XML's ending XML-tag </soap:Envelope>.
    I don't want to watch every packet's end like "if the end string is </soap:Envelope> then it is the last packet", I just simply want to know which is the last packet of that message.
    The TCP connection won't be closed after the message arrives, and let's say the HTTP header doesn't contain a Content-Length field.

    A TCP connection is just a stream of bytes. It doesn't care what those bytes are. HTTP is built on top of TCP and specifies the ability to make a request without closing the connection (HTTP 1.1 Keep Alive). So you need to understand the HTTP protocol, understand whether it's a Keep Alive connection or not, and then do the same thing a browser would to do understand when a reply has been completed and the connection is available for the next request. Otherwise, you'll just look like you're getting loads of unrelated data as you sniff the connection. Oh, and you'll probably need to understand the HTTP chunking protocol too.

  • HT4906 i am using aperture 3.3.2 on the current os and cannot connect to photo stream, why not

    why can I not use photo stream on my iMac?
    i am signed into icloud
    in aperture I click on turn on photo stream ... it sais enabling and comes back with
    Aperture was unable to connect to photo stream
    Peter

    You can still use PS using Aperture 3.3.2 and earlier but the window and its controls will likely be dimmed out in the iCloud pref pane, as its expcted 3.4
    Good idea, Clem, but I am using Photo Stream on 10.8.2 with Aperture 3.3.1 without problems. Even switching between Aperture 3.3.1 and Aperture 3.4 does not cause a problem. The controls are active in Aperture 3.3.1, but right now it takes a long time for the Photo Stream to be delivered, after turning it on. There is too much traffic in the iCloud.

  • Just installed icloud onto window 7 pc and only a few photos from ipad came through on photo stream why dont they all come through?

    just installed icloud onto window 7 pc and only a few photos from ipad came through to Photostream why dont they all come through?

    WOW! That font is difficult to read. But, see if this support document helps you http://support.apple.com/kb/TS3989. Photos stream is based on date and photos more than 30 days old are removed. Photostream is designed as a temporary storage to allow you to download the photos to the computer.

  • Iphoto imported photos from my ipad but not from the "photo stream"- why?

    I'm trying to get all files off my brother's old ipad before restoring it. I imported photos onto my computer using iphoto, but it didn't import the photos in the "photostream" on the ipad- why not? I saw that iphoto will only import photos that were taken on the ipad but I'm pretty certain these were. Thank you.

    Let me try and explain it this way.
    Say I have taken ten pictures, 1,2,3,4,5,6,7,8,9,10
    These were imported to iPhoto and went into an event it created called June 2013 Photostream. They were all imported and showed up in order 1,2,3,4,5,6,7,8,9,10
    Some of them I have now tagged faces in etc.
    When I go back now and look in the June 2013 Photostream I only see 1,3,4,5,6,9,10
    But if I look in the last 12 months album I still see 1,2,3,4,5,6,7,8,9,10 in the right place and the right order
    Pictures 5,6,7,8 all had my face tagged and when I look in my face album 5,6,7,8 all show in the right place in the right order.
    I have got iPhoto to rebuild the library etc and they do not go back to showing in the Photostream import folder.

  • Diginal Signatures don't transmit with XML Data, Why?

    I am trying to transmit the diginal signature on the form in adobe reader through email as a XML data source to its destination. But the object does not have any binding to the email. I need to send the signature so that I can pull the received email XML file into the form again with the signature to print a copy in house.
    How do you get the signatures to be bound to the data file that is sent via XML through an email system?

    You can't pull a signature into a file. That would imply signatures,
    once made, could be separated and the stuck on other documents that
    the user never saw and never signed!
    A signature is integral with the file. You need to submit the whole
    file. (Acrobat forms appear to submit sending only the signature
    portion of the file, but I can't see this for designer forms).
    From
    http://www.adobe.com/devnet/livecycle/articles/designer_coldfusion.html,
    "PDF [format] submits a package containing an embedded PDF file.
    Choose this format if the form contains a signature field..."
    Aandi Inston

  • I've an iMac with OS X 10.4.11. Sudden email problem: every received email has, after the header, 1 - 2 pages of technical data (e.g., Dkim-Signature, Domainkey-Signature, etc.) I don't know why this now happening, and I don't know how to get rid of it.

    I have an iMac using OS X 10.4.11. Beginning several days ago, all incoming emails have, after the usual email header and before the message appears, one to two pages of technical data (e.g., Dkim-Signature, Domainkey-Signature, Content-Transfer-Encoding, etc.). This is similar and more complex that the info one receives when an undeliverable email bounces back. I don't know where this stuff comes from, or how it came, and I don't know how to get rid of it. Any ideas? I'm something of a newbie to computers (um, what's a Tag?).

    That just sounds like the mail headers. Most people don't know (or care) about them so they're usually hidden.
    Check Mail -> Preferences -> Viewing -> Show header detail
    I'm guessing it's set to 'All'. Switch it to 'Default' or None as you prefer.

  • DataInputStream.close() is blocking while closing the thread's stream.Why?

    I have a DataInputStream in my thread as
    DataInputStream dis = new DataInputStream(System.in);
    I have written a method for closing that DataInputStream as
    public void closeStream(){
    dis.close();
    But when I call closeStream method from my program as
    t.closeStream();
    it blocks the program execution. I have to press 'Enter' to continue.
    Why is it so?
    Thanx in Advance.

    You're creating the DataInputStream around the standard input. Assuming you haven't reassigned System.in, I'm pretty sure that you can't close it. At least, you shouldn't be able to close the standard input.

  • I have a 16GB iPhone 4s and currently I have around 100MB left. It says my photos take up 6.34 GB   I really am unsure how because I only have 252 pictures on my phone (not including the 5 photos I've on my Photo Stream).Why does it take up so much space?

    I have less than a GB of apps and just over a GB with Other... To be fair I have around 22 videos which people have previously said in the past is my problem but I still can't see how because in total they all add up to 35.59... I've had a go deleting absolutely everything (including apps, photos, texts, history on the phone, websites etc) and still my phone is out of memory. my sister has about 200 photos and on her phone it only takes up around 3GB ?
    If anyone has any suggestions or ideas it would be appreciated...
    (I am very reluctant to putting all my photos on my computer and deleting them off of my phone at the moment because I don't trust they're safe incase one day my laptop is wiped or something).
    Thank you,
    Lauren

    Make a backup of your laptops hard drive to an external hard drive or a thumb drive.
    Videos take up a lot of memory.  One second of videos is like dozens of pictures.  How much time, in total minutes & seconds, do all 22 of these videos add up to?

  • I can't open my Photo Stream, Why?

    I have 938 photos on there and it will not open.  Please help me.  I have a iPhone 4

    Missed the window to edit my last post...
    ...also open iPhoto>Preferences>make sure the following items are checked as required: My Photostream, Automatic Import (optional for this issue), Automatic Upload (optional for this issue), Photo Sharing.  

Maybe you are looking for