Re: Evaluation for IDS

From: ¼ºÀ±±â Yune Sung (yune@kisa.or.kr)
Date: 09/29/01


Message-ID: <3BB51A32.39600CF8@kisa.or.kr>
Date: Sat, 29 Sep 2001 09:47:46 +0900
From: ¼ºÀ±±â Yune Sung <yune@kisa.or.kr>
To: hu jinhua <hujh@neusoft.com>
Subject: Re: Evaluation for IDS

Generally you can refer to Commom Criteria project, available at
http://www.commoncriteria.org
and there you can get latest versions od CC and Commom Evalauation
methodology,
quite a bit enormous reference regarding security fuctions and assurance
components...

additionally, specific IDS protection Profiles are released at
http://www.iatf.net/protection_profiles/intrusion.cfm

i wish you get all you want there...
truly,

hu jinhua ÀÛ¼º:
>
> I need help about testing methodology for IDS, or
> criteria about evaluating IDS. who can tell me about
> this.
> Someone who have knowledge about this please
> mail me. My E-mail address is hujh@neusoft.com.
> Thanks very much!

Yune Sung,
IDS Evaluation,
Korea Information Security Agency
------------------------------------------------
e-mail : yune@kisa.or.kr
          yune@netian.com
Fax : 82-2-405-5369
Tel : 82-2-405-5366
Cell : 82-11-706-7565
------------------------------------------------



Relevant Pages

  • IDS Assessment (was: Intrusion Prevention... probably something else at one point)
    ... scrutiny of all IDS features/technologies. ... Anomaly-type detection engines can ... weaknesses of each detection methodology (which is described in much ... attack d'jour with a cool sounding name and/or press ...
    (Focus-IDS)
  • RE: Intrusion Prevention
    ... Coverage what can it detect; this covers basic attacks, ... IDS purchase. ... While doing these implementations and while working in an IDS vendor I ... sometimes we're told that we cannot see the testing methodology upfront. ...
    (Focus-IDS)
  • Re: newbie questions
    ... I will say the same thing to you I sad to Dave Aitel - you need to read our methodology more carefully. ... We DO, however, understand that IPS is not IDS - I am not sure you do.... ... The NSS Group ...
    (Focus-IDS)
  • RE: Evaluation for IDS
    ... Subject: Evaluation for IDS ... The tcpdump files that shmoo has from the DefCon CTF networks ... offer a whole bunch of nasty traffic that you can use with ...
    (Focus-IDS)
  • Re: newbie quetsions
    ... >whether an IDS can take the load of millions of packets at once. ... Evaluation of IPS products raises a great challenge for the evaluator. ...
    (Focus-IDS)