IDS is producing an increased amount of false positive events about brute force attempts on the organization's mail server. How should the Snort rule be modified to improve performance?
Option D looks like the way to go. Tuning the count and seconds threshold could help filter out those pesky false positives without blocking legitimate traffic.
Muriel
1 months agoShelia
1 months agoHelene
1 days agoTerina
13 days agoAdela
17 days agoVerda
2 months agoAlita
1 months agoLeslie
1 months agoLawana
2 months agoAide
2 months agoVal
1 months agoMerlyn
1 months agoDaryl
2 months agoMagda
2 months agoGary
2 months agoJerry
3 months agoEladia
3 months agoTatum
3 months ago