Think you have a false positive on this rule?

Sid 1-41079

Message

PROTOCOL-SCADA IEC 104 traffic to/from EXTERNAL_NET

Summary

Impact

Detailed information

Affected systems

Ease of attack

False positives

False negatives

Corrective action

Upgrade to the latest non-affected version of the software.

Apply the appropriate vendor supplied patches.

Contributors

Additional References

  • blog.snort.org/2016/12/iec60870-5-104-protocol-detection-rules.html