"Abnormal Upload" Algorithm Issues
Love my firewalla gold, but it creates an excess of Abnormal Upload alerts that are not abnormal. Legitimate abnormal or other alerts thus get buried and not observed quick enough.
For example, I have many devices/services that upload a few megabytes several times a day... which is normal. But every time they do, it generates an alert. Cameras, IP phones, PLEX server, NAS, and IoT Devices are the majority of them.
The Abnormal Upload alert is useful for knowing actual "Abnormal" patterns, such as devices that only upload traffic a few times a week/month, large amounts of data, or haven't really uploaded any data as they're new and traffic patterns haven't been learned.
I'm curious how the algorithm really works, and how it can be tweaked in the future to eliminate false-positive alerts. I do like the feature, so I do not want to globally disable. Would help in the short-term if we're able to mute abnormal upload alerts per-device. The outbound domain-level mute is helpful, but there are often GCP/AWS services that are IP-only (no PTR records).
-
This document may have some information https://help.firewalla.com/hc/en-us/articles/360020926913-Abnormal-Upload-Alarms-Tutorial
Muting the alarm will definitely help. The algorithm behind is learning-based so it is one of those things may have a mind of its own.
-
I had already looked at that article, but thanks for sending. It's quite vague and doesn't really cover the touch points above.
Muting each alarm does nothing. In the 5 months I've had the FWG, it has not learned any device upload characteristics and just repeats the alerts daily.
I'll mute all abnormal upload notifications for now until it's more mature and/or device-level muting is enabled.
-
I know this is an older thread but it's still a problem. What I really want to be able to do is tune abnormal uploads to just larger uploads. I don't usually care about a few megabytes, but a few hundred MB is a different story. I don't want to mute most domains or IPs. I just need to mute everything below, say, 100MB.
-
The abnormal upload is behavioral instead of just having a limit. I do know in 1.51, we start tunning this, give it a try https://help.firewalla.com/hc/en-us/articles/7367027330195-App-Release-1-51
-
Yes, I've been playing around with it but it still isn't quite what I'm looking for. I'd love the behavior to take into account the amount of data as I mentioned. At the moment "low" is still producing too many alerts that just aren't useful to me. But I can't mute most of the host or IP addresses. I just really care about LARGE amounts of data being uploaded, possibly indicating data exfiltration in a ransomware attack.
Please sign in to leave a comment.
Comments
17 comments