Dear Ali,
That is a pity, since duplicate flow records are generally a problem for any analysis application. In your case, without seeing more flow records in your example, I suspect that the shown flow records have been preceded by a long range of (failed) login attempts, followed by a longer connection from the attacker’s port 1488. However, as said, it’s very hard to say that for sure at this moment, since the SSH attack model used by SSHCure is quite extensive and depends on a lot of contextual information.
Best regards,
—
Rick Hofstede
> On 08 Dec 2014, at 18:57, Kapucu, Ali <ak...@ke...> wrote:
>
> Rick,
>
> I am sending netflows from inside and outside interfaces because of Natting so i can correlate 10.x ip address with public addresses
>
> Thats why we are seeing 2 times.
>
> From: Rick Hofstede <r.j...@ut...>
> Sent: Monday, December 8, 2014 12:03 PM
> To: Kapucu, Ali
> Cc: ssh...@li...
> Subject: Re: [Sshcure-discuss] Flags under the flow
>
> Dear Ali,
>
> These flags represent the TCP flags, exported by the flow exporter for every shown flow record. There is however something strange going on: it seems that all flow records are duplicated. Can you verify why that is the case?
>
> Thanks,
>
> —
> Rick Hofstede
>
>> On 08 Dec 2014, at 13:52, Kapucu, Ali <ak...@ke... <mailto:ak...@ke...>> wrote:
>>
>> Aww sorry it is 2.4.1
>>
>> Sent from my iPhone, but not while driving because that's illegal under ORC 4511.204!
>>
>> On Dec 8, 2014, at 2:39 AM, Rick Hofstede <r.j...@ut... <mailto:r.j...@ut...>> wrote:
>>
>>> Dear Ali,
>>>
>>> Could you please upgrade your installation to v2.4.1? It will be much easier to help you based on that version, than based on v2.3.4.
>>>
>>> We’d be happy to hear from you again, especially in case of false positive detections.
>>>
>>> Thanks,
>>>
>>> —
>>> Rick Hofstede
>>>
>>>> On 08 Dec 2014, at 08:16, Kapucu, Ali <ak...@ke... <mailto:ak...@ke...>> wrote:
>>>>
>>>> It is 2.3.4
>>>>
>>>> Thanks
>>>>
>>>> Sent from my iPhone, but not while driving because that's illegal under ORC 4511.204!
>>>>
>>>> On Dec 8, 2014, at 2:10 AM, Rick Hofstede <r.j...@ut... <mailto:r.j...@ut...>> wrote:
>>>>
>>>>> Dear Ali,
>>>>>
>>>>> In order to answer your question properly, we have to know the version of SSHCure you’re running.
>>>>>
>>>>> Thanks,
>>>>>
>>>>> —
>>>>> Rick Hofstede
>>>>>
>>>>>> On 08 Dec 2014, at 06:13, Kapucu, Ali <ak...@ke... <mailto:ak...@ke...>> wrote:
>>>>>>
>>>>>> Hi,
>>>>>>
>>>>>> I would like to understand Flags under the flow and How SSHCure is telling its compromised.
>>>>>>
>>>>>>
>>>>>> Thanks
>>>>>>
>>>>>> Could you please explain their meanings
>>>>>>
>>>>>> for example;
>>>>>>
>>>>>> 19:47:58 0.268 220.177.198.43:3262 xxx.xxx.111.158:22 .A.RS. 3 128
>>>>>> 19:47:58 0.268 220.177.198.43:3262 xxx.xxx.111.158:22 .A.RS. 3 128
>>>>>> 19:48:01 10.144 xxx.xxx.111.158:22 220.177.198.43:1488 .AP.S. 18 2067
>>>>>> 19:48:01 10.144 xxx.xxx.111.158:22 220.177.198.43:1488 .AP.S. 18 2067
>>>>>> 19:48:01 9.920 220.177.198.43:1488 xxx.xxx.111.158:22 .AP.S. 15 2603
>>>>>> 19:48:01 9.920 220.177.198.43:1488 xxx.xxx.111.158:22 .AP.S. 15 2603
>>>>>> 19:48:02 12.256 220.177.198.43:1488 xxx.xxx.111.158:22 .APRS. 17 2683
>>>>>> 19:48:02 12.256 220.177.198.43:1488 xxx.xxx.111.158:22 .APRS. 17 2683
>>>>>> 19:48:14 0.000 xxx.xxx.111.158:22 220.177.198.43:1488 .AP..F 1 40
>>>>>> 19:48:14 0.000 xxx.xxx.111.158:22 220.177.198.43:1488 .AP..F 1 40
>>>>>> 19:48:14 0.256 xxx.xxx.111.158:22 220.177.198.43:1586 .A.RS. 2 84
>>>>>> 19:48:14 0.256 xxx.xxx.111.158:22 220.177.198.43:1586 .A.RS. 2 84
>>>>>> 19:48:14 0.256 220.177.198.43:1586 xxx.xxx.111.158:22 .A.RS. 3 128
>>>>>> 19:48:14 0.000 220.177.198.43:1488 xxx.xxx.111.158:22 .A.R.. 2 80
>>>>>> 19:48:14 0.256 220.177.198.43:1586 xxx.xxx.111.158:22 .A.RS. 3 128
>>>>>> 19:48:14 0.000 220.177.198.43:1488 xxx.xxx.111.158:22 .A.R.. 2 80
>>>>>> 19:48:14 0.244 220.177.198.43:1586 xxx.xxx.111.158:22 .A.RS. 3 128
>>>>>> 19:48:14 0.244 220.177.198.43:1586 xxx.xxx.111.158:22 .A.RS. 3 128
>>>>>>
>>>>>>
>>>>>> ------------------------------------------------------------------------------
>>>>>> Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
>>>>>> from Actuate! Instantly Supercharge Your Business Reports and Dashboards
>>>>>> with Interactivity, Sharing, Native Excel Exports, App Integration & more
>>>>>> Get technology previously reserved for billion-dollar corporations, FREE
>>>>>> http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk_______________________________________________ <http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk_______________________________________________>
>>>>>> Sshcure-discuss mailing list
>>>>>> Ssh...@li... <mailto:Ssh...@li...>
>>>>>> https://lists.sourceforge.net/lists/listinfo/sshcure-discuss <https://lists.sourceforge.net/lists/listinfo/sshcure-discuss>
|