[Bro-Dev] [JIRA] (BIT-1138) UDP scan detection generates a large number of triggers

aashish (JIRA) jira at bro-tracker.atlassian.net
Fri Feb 21 12:33:38 PST 2014


    [ https://bro-tracker.atlassian.net/browse/BIT-1138?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15582#comment-15582 ] 

aashish commented on BIT-1138:
------------------------------

John, 

I am sending you the tar ball of the site-policy files in a direct email. 

Aashish 


-- 
Aashish Sharma	(asharma at lbl.gov) 				 
Cyber Security, 
Lawrence Berkeley National Laboratory  
http://go.lbl.gov/pgp-aashish 
Office: (510)-495-2680  Cell: (510)-612-7971


> UDP scan detection generates a large number of triggers
> -------------------------------------------------------
>
>                 Key: BIT-1138
>                 URL: https://bro-tracker.atlassian.net/browse/BIT-1138
>             Project: Bro Issue Tracker
>          Issue Type: Problem
>          Components: Bro
>            Reporter: Robin Sommer
>             Fix For: 2.3
>
>         Attachments: CPU-all-scan-policies.png, Memory-All-Scan-Policies.png
>
>
> These triggers then cause high CPU load. We had a fix already but I'm not sure if it has been confirmed that it solved the problem?



--
This message was sent by Atlassian JIRA
(v6.2-OD-09-036#6252)


More information about the bro-dev mailing list