False Positives

CS-MARS considers a false positive an attack that was unsuccessful against the target, either because the host was not vulnerable to the attack or because other products prevented the attack from succeeding. This is somewhat of a misnomer, because the real definition of a false positive is when a product incorrectly identifies an attack, when in reality it was not an attack.

For example, if legitimate communication between a network printer and a host is incorrectly detected by your network-based IDS as an attack, this is, by definition, a false positive. However, this does not fit the definition used by CS-MARS. On the other hand, if a hacker launches an attack against your web server, and your network-based IDS accurately detects the attack but your web server is protected against the attack with updated software, CS-MARS considers this a system-determined false positive. By definition, it is not really a false positive; instead, it is a positively detected attack that was unsuccessful.

You need to understand the differences between the true definition of a false positive and the definition used by CS-MARS.

Figure 1-5 shows the following three types of false positives that are used in CS-MARS:

• Unconfirmed false positive type

• User-confirmed false positive type

• System-determined false positive type

Figure 1-5 False Positive Page

Figure 1-5 False Positive Page

CS-MARS uses an integrated vulnerability assessment (VA) system that can be enabled on all or part of your network. The VA system more accurately determines whether attacks are real and can make the false positives described in this section more accurate. The system is designed to determine the following items:

• Operating system

• Version and patch level

• Servers that are running

Unconfirmed False Positives

An unconfirmed false positive is created when CS-MARS believes, but is not certain, that a host is not vulnerable to an attack. For example, the first unconfirmed false positive in Figure 1-5 is related to event "WWW WinNT cmd.exe Exec," which is a known vulnerability in older versions of Microsoft's IIS web server. Part of the investigation CS-MARS performs, when enabled, is a vulnerability assessment of the hosts under attack. This allows CS-MARS to determine things such as host operating system, patch level, services that are running, and versions of the services. If the vulnerability assessment shows that the targeted system is not vulnerable to the attack type, CS-MARS labels it as an unconfirmed false positive.

Periodically, you must check the unconfirmed false positives and confirm the results of the vulnerability assessment. Click the question mark to see why CS-MARS believes this is a false positive. Figure 1-6 shows the resulting window.

Figure 1-6 Unconfirmed False Positive

3 h1lps://10.D.0.91 [mars Ic] Take Positive Confirmation Microsoft Internet fxplorer

X

|j||

üU4Ad*iciri*: nurHe

L$4Hi: Aifmini

Wrfltor (pnflimi

£vnnt Yypo: www WrnNT cmd<>n E>«c

IIdíI: groo

Vulnarabllltv dEtarmlnoUem: f alte Pomíyo

(a) NO hottiflfo in MAftfc database,

(b) NESSUS test resUt:

KOI VuVierafcJe: Th» web ¡e«verdoei r,ot ellow a unieoda encodad URL raquastto ex a Cute «rb(tr*ry commandi-

| C.«.l I

EE]

Mure Iiifcmiiotion:

Affected plotfonns for avant WWW WlnNT cmd.eKe Ekbc;

¡OS | Application Program

|progrn

m Ver»Ion

I

Microsoft Windows HT«1.0 AKY HS4.0 ANY

ANY

Microsoft Windows £006 Server ANY ttS 5.0 AMf

ANY

Microsoft Windows 2000 Servar any Sí>i tts S.O any

ANY

Microsoft Windows 2000 Servar any hp£ US £.0 any

ANY

Microsoft Windows 2000 Advantad Servar AMT ttS S.O any

ANY

Microsoft Windows £000 Advanced Server mi SPl ttS S.O AMY

ANY

Microsoft Windows 2000 Adv«n«d Server fitn tu lis S.O any

ANY

Microfoft windowf ?DOO Prof»ííional arrr ttS ».0 any

ANY

Mic»o(íft windowí ÍOOO KrofMMonal any $Pi ttS ».0 any

ANY

Microfoft wiftdowí ÍOOO íroííísiofial ANY ttS ».0 any

ANY

M.CrOÍOÍt Windows MT 4.0 ANY t[3 5.0 AMT

ANY

Microfod Wiftdowí MT OtflO* P** 4 .0 ANY ItS 4.0 ANY

ANY

MiürtíOÍt Windows HT QjftOA 4.0 ANY ItS 5-0 AMY

ANY

üomt

5

mat

User-Confirmed False Positives

After you look at an unconfirmed false positive and agree with the determination CS-MARS has made, you confirm the false positive.

A user-confirmed false positive is simply your agreement that CS-MARS is correct in saying that a host is not vulnerable to a type of attack.

System-Determined False Positives

A system-determined false positive occurs when a device reports that it has stopped an attack. This occurs when some reporting devices indicate an attack while at least one other indicates the attack failed, or when the targeted host sends a log that the attack failed.

Consider the following example:

• An attacker (or worm) attempts a directory traversal attack against your Microsoft IIS web server. A directory traversal attack occurs when the attacker tricks the web server into accessing files outside the designated directories for the web server. Most commonly, this is an attempt to run Windows system files, such as the command prompt (cmd.exe).

• Several devices might report on this attack. Your firewall and routers will report on the traffic flow. Your IDS might identify the attack but might not be configured to respond to it.

• Your web server might have host protection software installed, such as Cisco Security Agent, or it might be patched so that it's not vulnerable to the attack. In this case, when the web request attack is sent to the web server, the server responds with an HTML response code, such as 404.

• You might also have an IPS that is configured to drop this type of attack. In this case, the attack never reaches the destination web server.

In this example, CS-MARS understands the topology of your network and knows when a device in the path of an attack prevents the attack from succeeding.

Figure 1-7 shows a system that was determined to be false positive.

Figure 1-7 System Determined to Be False Positive

Figure 1-7 System Determined to Be False Positive

Continue reading here: Who Is Affected by the GLB Act

Was this article helpful?

0 0