From: Tim Zakharov <tzakharov@protonmail.com>
To: "dbl@lists.ipfire.org" <dbl@lists.ipfire.org>
Subject: Malware category IPS questions and comments
Date: Sun, 08 Mar 2026 15:30:42 +0000 [thread overview]
Message-ID: <qEFZ_3_YQRKXAFiVx_U29UFj6K7fapeGCkXrrsTObRAXxJcXf-qS7ykeANpSynZYch4mZpH79VGJ-h-L2-eIKpTt-4xxP1m5HtpiTEcQxV8=@protonmail.com> (raw)
Hi, since enabling the Malware category in the IPS, I am getting a lot of hits in the logs that seem completely unrelated to Malware.
For example, just this morning between 9:36:58 and 9:36:59, I received 20 hits with the source being my Windows 11 desktop and destination being IPFire, all on port 53.
The rule is:
IPFire DBL [Malware] Blocked DNS Query
Type:
Potential Corporate Privacy Violation
SID:
406786433
I cannot tell what triggered these hits, but I can tell you I was not doing anything that would trigger Malware on my system.
Is there any way to determine what triggers Malware hits (the originating rule, for example?)
If I go to Customize IPS Rulesets and show the IPFire DBL Malware category, there are only 4 checkboxes:
IPFire DBL [Malware] Blocked DNS Query IPFire DBL [Malware] Blocked HTTP Request
IPFire DBL [Malware] Blocked TLS Connection IPFire DBL [Malware] Blocked QUIC Connection
So at the moment there is no granularity to uncheck a particular rule that might be filling my logs with false positives.
Also, I see no way how I could report this as a false positive because there is no granularity to tell which rule is triggering it.
I considered posting this in the forums, but I saw Michael telling someone else "I would appreciate if you joined our DBL mailing list and share your thoughts there as this support forum is not the right place." so I thought I should post here instead of the forum.
Thanks,
Tim
next reply other threads:[~2026-03-08 15:30 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-08 15:30 Tim Zakharov [this message]
2026-03-09 10:55 ` Michael Tremer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='qEFZ_3_YQRKXAFiVx_U29UFj6K7fapeGCkXrrsTObRAXxJcXf-qS7ykeANpSynZYch4mZpH79VGJ-h-L2-eIKpTt-4xxP1m5HtpiTEcQxV8=@protonmail.com' \
--to=tzakharov@protonmail.com \
--cc=dbl@lists.ipfire.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox