Skip to main content
bobm
New Member
September 30, 2014
Question

Google found unusual traffic

  • September 30, 2014
  • 5 replies
  • 9068 views
Today we started getting error messages from Google saying they detected " unusual traffic" from our network, and blocking our searches. I' ve done some research, and will be looking for malware, etc on the users' PCs, but also want to look at the traffic. We' re running a 60C with minimal features running (pretty much UTM only) due to memory issues. I' m going to enable IPS for a while tomorrow to see if anything hits, but wanted to know if anyone has run across this and had any ideas on what to look for in traffic logs (apps, UDP ports, etc) since Google doesn' t give any info on destination addresses, types of traffic, etc - just " unusual" .

    5 replies

    netmin
    New Member
    September 30, 2014
    You could search for unusual google traffic/usage in your webfilter logs, robots on your network, etc. https://support.google.com/websearch/answer/86640?hl=en
    bobm
    bobmAuthor
    New Member
    September 30, 2014
    Thanks netmin, I had looked at that page, and reported the situation to Google as well. And virus scans this morning came up clean. But what I was wondering was if there was a particular signature to look for in the FGT logs - addresses, applications, UDP ports, etc. that would help me narrow down my search for the culprit. Other than just " who has the most outbound traffic" . Seems to be OK today though.
    Istvan_Takacs_FTNT
    Staff
    Staff
    September 30, 2014
    " unusual traffic" can also mean that someone might' ve picket your address range to target another system. Since the attacker is not interested in flooding his/her own system with the answer, the source could be faked for something unrelated. Check the traffic log also for any " unusual traffic" coming in.
    omkam
    Visitor III
    May 17, 2023

    Is this related to fortigate issue?

    netmin
    New Member
    September 30, 2014
    They are mainly referring to web crawlers or robots (like click bots). That was usually http or https traffic to google servers. I would investigate 24h high or constant session counts from individual PCs (i.e. using FortiView graphs/stats on 5.2.x) or session history graphs first. FortiView does also allow for more drill down. Unfortunately they don' t state more in details _when_ one gets flagged (invalid/suspicious browser agents, constant query rates or special query types).
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!