Re: Signature and Traffic generation

From: Brian (bmc@snort.org)
Date: 03/16/02


Date: Fri, 15 Mar 2002 23:47:56 -0500
From: Brian <bmc@snort.org>
To: John S Flowers <jflowers@well.com>

According to John S Flowers:
> Very well said. The ability to compare what was found by the IDS to what
> is a real attack on your network against a real, vulnerable system, is the
> hallmark of what should be required for an alarming system benchmark to
> succeed and have validity.

I donno about you, but I would like to know if someone tries to attack
me, regardless of how secure my network is as seen by my IDS. While
raising priority of alerts for systems that look to be vulnerable to
attacks is a good thing, ignoring attacks just because some vendor
thinks I'm not vulnerable is not.

Last I checked, all of the IDS vendors are human. Humans make
mistakes. I'd like to leave the decisions of what to ignore to someone
that knows more about my network (me) rather than my IDS.

-brian



Relevant Pages

  • RE: IDS that retaliates.
    ... launches an attack and suddenly he looses his connection .. ... a genius to work out an IDS is in play... ... Using RST packets - be careful with things like SYN floods as sending a ... "Perfecting the Art of Network Security" ...
    (Focus-IDS)
  • RE: IDS that retaliates.
    ... launches an attack and suddenly he looses his connection .. ... a genius to work out an IDS is in play... ... Using RST packets - be careful with things like SYN floods as sending a ... "Perfecting the Art of Network Security" ...
    (Security-Basics)
  • RE: Announcement: Alert Verification for Snort
    ... I think what you are really after is to be found in a good security ... combining VA and IDS will ... 100% accurate across your network. ... accuracy to determine if an "event" is really an attack likely to cause ...
    (Focus-IDS)
  • Re: "false positive" inanity
    ... So Mr. Snyder is asking for an IDS that does not need to be configured? ... maximum control of his/her network. ... attack. ... > assuming that it is not an intrusion. ...
    (Focus-IDS)
  • IDS Assessment (was: Intrusion Prevention... probably something else at one point)
    ... scrutiny of all IDS features/technologies. ... Anomaly-type detection engines can ... weaknesses of each detection methodology (which is described in much ... attack d'jour with a cool sounding name and/or press ...
    (Focus-IDS)