Prelude-correlator & Lua help

[email protected]
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <OF3ED813A5.FF08981E-ON0A257540.00702D47-0A257540.00719DED@thdfsg.com>
I'm continuing to whittle down the false positives from my particular 
prelude
setup.  Right now I'm running into an issue with prelude-correlator and 
postfix/prelude-lml

Events like the following (probably a spam-bot in this case)  in the 
maillog are 
correctly being caught by prelude-lml and put into the prelude database 

Jan 16 08:32:44 mail postfix/smtpd[28030]: lost connection after RCPT from 
foo.bar.net[10.10.10.10] 


Text | Severity | Completion | Type | Description
Mail server suspicious access | low | failed | other | Lost connection 
from 10.10.10.10 after RCPT action 


The trouble is that this log is also tripping prelude-correlator's 
firewall rule #2

-- Firewall correlation (2 of 2)
-- This rule begins a timer for every event that contains a source and a 
target
-- address which has not been matched by an observed packet denial.  If a 
packet
-- denial is not observed in the next 10 seconds, an event alert is 
generated.

And of course, since postfix has to receive connections from outside to
receive email, there is no corresponding firewall drop event.

So, keeping in mind that I don't speak lua, how can I get 
prelude-correlator to skip
correlating certain events that I know will be tripped by other sensors, 
but will not
have a corresponding firewall drop event?


Dean Takemori
Tech Support Supervisor
TD Food Group
[email protected]
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.