Wfilter sending false alarm

General discussion about WFilter ICF features, problems, configuration issues etc.

Moderators: imfirewall, gengw2000

kksg2000
Posts: 17
Joined: Thu Jun 21, 2012 3:59 am

Wfilter sending false alarm

Postby kksg2000 » Mon Jul 09, 2012 1:31 am

Hi,

I installed Wfilter (chinese) on my china server. I have been receving manay false alarms from the system. I am receving notifications on application launch like FreeCast, QQlive, 脱兔下载 and 浩方对战平台. I checked on many of these computers and couldn't find these software on them except for a few computers which are running QQ messengers (not the QQlive) whereas the rest do not have any of these related software installed at all.



Could you help?



Thanks



kksg2000
Posts: 17
Joined: Thu Jun 21, 2012 3:59 am

Wfilter sending false alarm

Postby kksg2000 » Mon Jul 09, 2012 1:57 am

kksg2000 wrote: Hi,

I installed Wfilter (chinese) on my china server. I have been receving manay false alarms from the system. I am receving notifications on application launch like FreeCast, QQlive, 脱兔下载 and 浩方对战平台. I checked on many of these computers and couldn't find these software on them except for a few computers which are running QQ messengers (not the QQlive) whereas the rest do not have any of these related software installed at all.



Could you help?



Thanks








I put my computer on the monitor list and I recevied XunLei,QQDownload,Flashget alert. I do not have these software installed in my computer.



Could you advise?

gengw2000
Posts: 281
Joined: Mon Sep 07, 2009 11:11 pm

Wfilter sending false alarm

Postby gengw2000 » Mon Jul 09, 2012 2:13 am

QQ messenger can produce "QQLive" and "QQDownload" traffic, because QQ messenger has integrated so many features.



But I am not sure why you have "FreeCast", 脱兔下载 and 浩方对战平台.



gengw2000
Posts: 281
Joined: Mon Sep 07, 2009 11:11 pm

Wfilter sending false alarm

Postby gengw2000 » Mon Jul 09, 2012 2:19 am

Can you run a protocol bandwidth report to check the bandwidth details of these three patterns?

kksg2000
Posts: 17
Joined: Thu Jun 21, 2012 3:59 am

Wfilter sending false alarm

Postby kksg2000 » Mon Jul 09, 2012 3:12 am

gengw2000 wrote: Can you run a protocol bandwidth report to check the bandwidth details of these three patterns?



Hi,

I attached the report. I had put in the english names next to the chinese characters for your reference. I do not know how this is going to help me. Please kindly advise.



Thanks.



Attached files report.zip (7.6 KB) 

gengw2000
Posts: 281
Joined: Mon Sep 07, 2009 11:11 pm

Wfilter sending false alarm

Postby gengw2000 » Mon Jul 09, 2012 5:35 am

As you can see, the 10th bandwidth is 0.408MB in total. It means other false alarm protocols are less than 0.408M.



I recommend you to ignore protocols <1M, because 1MB traffic can not do anything useful in practice.



We will setup a bandwidth threshold of alert trigger in later versions of WFilter to reduce false alarms.


Return to “WFilter ICF”

Who is online

Users browsing this forum: No registered users and 21 guests