IDS Correlation
From: Àî»Ô (huili@sei.xjtu.edu.cn)Date: 03/22/00
- Previous message: Kerberus: "RE: *ICN - A Conspiracy of Inertia?"
- Next in thread: Kohlenberg, Toby: "RE: IDS Correlation"
- Reply: Kohlenberg, Toby: "RE: IDS Correlation"
- Reply: Matthew F. Caldwell: "RE: IDS Correlation"
- Reply: Oliver Petruzel: "RE: IDS Correlation (threat management)"
- Reply: Keith T. Morgan: "RE: IDS Correlation"
- Reply: Matthew F. Caldwell: "RE: IDS Correlation"
- Reply: John S Flowers: "Re: IDS Correlation"
- Reply: Keith T. Morgan: "RE: IDS Correlation"
- Reply: eddonega@WellsFargo.COM: "RE: IDS Correlation"
- Reply: Jared A. Tucker: "RE: IDS Correlation"
- Reply: Matthew F. Caldwell: "RE: IDS Correlation"
- Reply: Keith T. Morgan: "RE: IDS Correlation"
- Reply: Jared A. Tucker: "RE: IDS Correlation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 22 Mar 2000 10:49:45 +0800 From: Àî»Ô <huili@sei.xjtu.edu.cn> To: "focus-ids@securityfocus.com" <focus-ids@securityfocus.com>
hi,all
Recently I am focus on IDS correlation,but I am always thinking about the questions:
1.Can correlation definitely improve the performance such as precison?
2.Maybe a comprehensive knowledge base about all kinds of IDS's alerts is essential to correlation,but how can we acquire it?
3.Supposed that we have the knowledge base,which kinds of method should we take to do correlation?
welcome all kinds of comments about correlation.
- Previous message: Kerberus: "RE: *ICN - A Conspiracy of Inertia?"
- Next in thread: Kohlenberg, Toby: "RE: IDS Correlation"
- Reply: Kohlenberg, Toby: "RE: IDS Correlation"
- Reply: Matthew F. Caldwell: "RE: IDS Correlation"
- Reply: Oliver Petruzel: "RE: IDS Correlation (threat management)"
- Reply: Keith T. Morgan: "RE: IDS Correlation"
- Reply: Matthew F. Caldwell: "RE: IDS Correlation"
- Reply: John S Flowers: "Re: IDS Correlation"
- Reply: Keith T. Morgan: "RE: IDS Correlation"
- Reply: eddonega@WellsFargo.COM: "RE: IDS Correlation"
- Reply: Jared A. Tucker: "RE: IDS Correlation"
- Reply: Matthew F. Caldwell: "RE: IDS Correlation"
- Reply: Keith T. Morgan: "RE: IDS Correlation"
- Reply: Jared A. Tucker: "RE: IDS Correlation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|