Skip to content

Comments

Extend queryPeriod & avoid redundancies#11

Open
Robin-Haeussler wants to merge 1 commit intof-bader:masterfrom
Robin-Haeussler:patch-1
Open

Extend queryPeriod & avoid redundancies#11
Robin-Haeussler wants to merge 1 commit intof-bader:masterfrom
Robin-Haeussler:patch-1

Conversation

@Robin-Haeussler
Copy link

Hi @f-bader, I believe I've found a potential blindspot in the detection, due to a too short queryPeriod based on the time span set in your query. Let ,me explain this via a fictional example: The enumeration event happens at 11:55 and the GetBlob event at 12:03, so the detection should hit on those events in theory. If the detection runs at 12:00, nothing happens since only one event (enumeration) occured thus far. If it then runs at 12:10 again, due to its 10m queryFrequency, it picks up the second event (GetBlob at 12:03), however it will not hit since the enumeration has slipped out of the lookback (happened 15m ago, but our queryPeriod is only 12m). So to solve this, what do you think about this proposed change to queryPeriod? The change to the query with new line 36 would eliminate potential redundant alerting as a result of the increased queryPeriod.

Increased queryPeriod from 12 minutes to 22 minutes to counter a potential blindspot.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant