Snot/state [WAS: Re: Signature and Traffic generation]
From: Greg Shipley (gshipley@neohapsis.com)Date: 03/16/02
- Previous message: Kurt Seifried: "Re: Possibility to cheat integrity checking?"
- In reply to: John S Flowers: "Re: Signature and Traffic generation"
- Next in thread: John S Flowers: "Re: Snot/state [WAS: Re: Signature and Traffic generation]"
- Next in thread: Brian: "Re: Signature and Traffic generation"
- Next in thread: Robert Graham: "Re: Signature and Traffic generation"
- Reply: John S Flowers: "Re: Snot/state [WAS: Re: Signature and Traffic generation]"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 15 Mar 2002 17:50:21 -0600 (CST) From: Greg Shipley <gshipley@neohapsis.com> To: focus-ids@securityfocus.com
On Fri, 15 Mar 2002, John S Flowers wrote:
> Again, Snot does far less than this and generates almost exactly the
> same bogus alerts. I'd suggest using it (or a tool like it) against your
> IDS and see what happens. If the IDS fails to properly categorize most
> of the attacks as invalid, you'll at least have some confidence you can
> ascribe to the alarms when performing correlation on the backend. It
> doesn't necessarily mean the IDS is useless, just that it's output
> cannot be trusted to the same degree as an IDS that properly identifies
> bogus attacks.
...or that you haven't turned on the state engine.
If your IDS has a feature to track state (almost all do now), enable it,
and you're on your way to solving the snot problem.
-Greg
- Previous message: Kurt Seifried: "Re: Possibility to cheat integrity checking?"
- In reply to: John S Flowers: "Re: Signature and Traffic generation"
- Next in thread: John S Flowers: "Re: Snot/state [WAS: Re: Signature and Traffic generation]"
- Next in thread: Brian: "Re: Signature and Traffic generation"
- Next in thread: Robert Graham: "Re: Signature and Traffic generation"
- Reply: John S Flowers: "Re: Snot/state [WAS: Re: Signature and Traffic generation]"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|