IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  [FP handling] Long Duration Flow Detected containing Web.SecureWeb

    Posted Tue July 12, 2022 05:07 AM
    Hi,

    In our deployment, we always have offenses (usually with low magnitude) triggered by the rule "Long Duration Flow Detected containing Web.SecureWeb"

    In this new cloud-based world, it is quite common if an application (even components of windows) are constantly connected to some web service (we usually see addresses from Microsoft's /10 network and Facebook). I don't want to include the whole /10 or even /8 Azure subnet, but I would like to handle this common traffic as FP.

    Any idea, on how to modify the rule for this? I'm sure we are not the only ones with this issue. Of course, it is possible at other places, this rule is simply turned off :)

    Thank you
    Laszlo
    ​​

    ------------------------------
    Vladx(x)
    ------------------------------


  • 2.  RE: [FP handling] Long Duration Flow Detected containing Web.SecureWeb

    Posted Sun July 17, 2022 05:52 AM
    Hello @Vladx(x),

    This rule is important i think, it pop when the flow duration is greater than 48 hours and the context is not local to local...

    Maybe you can try to create a Reference Set or Reference Map as an Exception list of what is local to you on your clouds.

    Hope this helps,
    Regards
    zoldax


    ------------------------------
    @zoldax

    https://www.youracclaim.com/users/pascal-weber.029e134d/badges
    ------------------------------



  • 3.  RE: [FP handling] Long Duration Flow Detected containing Web.SecureWeb

    Posted Mon July 18, 2022 02:49 AM

     

     

    Hi,

     

    The problem is, the „Good" clouds are huge nowdays. As I said for example MS or FB uses huge subnets for these services (like a /10 in case of MS) and I cannot find a good list of legitimate destinations to create a good FP filter for this specific rule, so I'm looking for some adivce from someone also facing with this issue

     

    Thank you

    Laszlo