Security e-Series
1753797 Members
8029 Online
108805 Solutions
New Discussion

Re: Filter 7120 false positives with Windows TCP keepalives

 
recallscottwalk
New Member

Filter 7120 false positives with Windows TCP keepalives

Have a question about the following filter, which we're seeing a lot of false positives on:

7120: TCP: Segment Overlap With Different Data, e.g., Fragroute

 

The description for the filter says that it does not include the one garbage octet for TCP keepalives, but it appears that it is indeed firing for Windows TCP keepalive messages.  Packet traces I've taken show that the sequence number of the keep-alive packet is one less than the current sequence number, with 0x00 as the payload.  Yet filter 7120 still fires for that packet.

 

Is this confirmed to be a problem?  Will most likely disable this rule, but wanted to see if there was a fix.

 

Thanks in advance,

Mike

 

1 REPLY 1
Dan Nelson_6
New Member

Re: Filter 7120 false positives with Windows TCP keepalives

Yes, filter 7120 isn't very good.  They tried to fix it again in June ( http://threatlinq.tippingpoint.com/blog/?p=2095 ) but it didn't help.  Just disable it.