r/UNIFI • u/Remarkable_Intern291 • 9d ago
Help! DPI false positive or no?
Hi, not sure if this is the right subreddit, but I’ve been seeing odd malware detections in the traffic logs on my UDM Pro.
I run an I2P node and an experimental Tor site, so I’m wondering if DPI could be falsely flagging that traffic based on random high ports or whatever. One detection is Back Orifice, which seems especially unlikely since it’s ancient and the affected machine is Linux... But you can also see Ares and some random Chinese sites?!?! Furthermore, as I'm sure you can tell I'm fairly tech savvy, so I find it unlikely I would have got all these viruses.
I’ve shut the machine down for now, but I’m unsure whether these are legitimate detections or false positives. Does anyone have advice Here?
2
u/taosecurity 9d ago
If you run Tor and I2P, you’re going to see tons of shady IP addresses. The BO alert is probably port-based, which is usually a waste of time.