6 ms·
You'll never really know your success rate though. You could have had machines compromised for years with small amounts of traffic.
by fujiters 9y ago
You'll never really know your success rate though. You could have had machines compromised for years with small amounts of traffic.
- tobltobs 9y agoI guess he doesn't mean that he detected all infected machines but that near 100% of machines which triggered the alarm were indeed infected.
- antoinealb 9y agoThat's a bad metric though. You could miss a lot of infected hosts.
- bauerd 9y agoOutbound traffic probably wasn't their only heuristic
- marcosdumay 9y agoThat is the single most important metric when you want to create an alert.
- et2o 9y agoHigh positive predictive value. Unknown sensitivity.
- linsomniac 9y agoWhat I meant by that statement was that of the system compromises that we detected, nearly 100% of them were detected through the SSH outgoing connections alert. Yes, there could have been compromises that went entirely undetected for years (we had a really high retention, so most customers stayed with us for 5+ years), so we had a good window to detect issues. Probably the next biggest notification of compromise was alerts about spam on our network. Mostly that was an e-mail account compromise rather than system level. But there are a ton of false positives on spam alerts, particularly AOL alerts were almost always about legitimately sent e-mails.
- ASalazarMX 9y agoThey could lower the threshold until they get an acceptable proportion of false positives, but I wouldn't want to be one of those false positives.