public inbox for dbl@lists.ipfire.org
 help / color / mirror / Atom feed
From: Tim Zakharov <tzakharov@protonmail.com>
To: "dbl@lists.ipfire.org" <dbl@lists.ipfire.org>
Subject: Malware category IPS questions and comments
Date: Sun, 08 Mar 2026 15:30:42 +0000	[thread overview]
Message-ID: <qEFZ_3_YQRKXAFiVx_U29UFj6K7fapeGCkXrrsTObRAXxJcXf-qS7ykeANpSynZYch4mZpH79VGJ-h-L2-eIKpTt-4xxP1m5HtpiTEcQxV8=@protonmail.com> (raw)

Hi, since enabling the Malware category in the IPS, I am getting a lot of hits in the logs that seem completely unrelated to Malware.

For example, just this morning between 9:36:58 and 9:36:59, I received 20 hits with the source being my Windows 11 desktop and destination being IPFire, all on port 53.  
The rule is:
IPFire DBL [Malware] Blocked DNS Query
Type:
Potential Corporate Privacy Violation
SID:
406786433

I cannot tell what triggered these hits, but I can tell you I was not doing anything that would trigger Malware on my system.

Is there any way to determine what triggers Malware hits (the originating rule, for example?)

If I go to Customize IPS Rulesets and show the IPFire DBL Malware category, there are only 4 checkboxes:
IPFire DBL [Malware] Blocked DNS Query		IPFire DBL [Malware] Blocked HTTP Request
	IPFire DBL [Malware] Blocked TLS Connection		IPFire DBL [Malware] Blocked QUIC Connection

So at the moment there is no granularity to uncheck a particular rule that might be filling my logs with false positives.

Also, I see no way how I could report this as a false positive because there is no granularity to tell which rule is triggering it.

I considered posting this in the forums, but I saw Michael telling someone else "I would appreciate if you joined our DBL mailing list and share your thoughts there as this support forum is not the right place." so I thought I should post here instead of the forum.

Thanks,
Tim






             reply	other threads:[~2026-03-08 15:30 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-03-08 15:30 Tim Zakharov [this message]
2026-03-09 10:55 ` Michael Tremer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='qEFZ_3_YQRKXAFiVx_U29UFj6K7fapeGCkXrrsTObRAXxJcXf-qS7ykeANpSynZYch4mZpH79VGJ-h-L2-eIKpTt-4xxP1m5HtpiTEcQxV8=@protonmail.com' \
    --to=tzakharov@protonmail.com \
    --cc=dbl@lists.ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox