Re: Snort Timestamps Out of Sequence

"Joel Esler \(jesler\) via Snort-devel" <[email protected]> Mon, 6 May 2019 13:44:04 +0000
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <[email protected]>
Hey Alan,

My "off the cuff" theory, without looking at your Snort configuration and requesting a full traffic reassembly is that something was holding the connection open (for 7 minutes) (keep-alive?) and Snort is reassembling the HTTP session in the background into what we call a "pseudo" packet.  A large reassembled stream.  That's what your rule alerted on, and should have logged it to disk.




--
Joel Esler
Manager, Communities Division
Cisco Talos Intelligence Group
http://www.talosintelligence.com

On May 6, 2019, at 9:16 AM, ROTNEMER, ALAN H <[email protected]<mailto:[email protected]>> wrote:

Is there some explanation as to why the alert took over 7 minutes to publish? Could Snort be waiting on anything in order to complete the alert?

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!