RE: IDS Correlation
From: Kohlenberg, Toby (toby.kohlenberg@intel.com)Date: 03/22/02
- Previous message: Àî»Ô: "IDS Correlation"
- Maybe in reply to: Àî»Ô: "IDS Correlation"
- Next in thread: Matthew F. Caldwell: "RE: IDS Correlation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Kohlenberg, Toby" <toby.kohlenberg@intel.com> To: "'??'" <huili@sei.xjtu.edu.cn>, "'focus-ids@securityfocus.com'" <focus-ids@securityfocus.com> Date: Thu, 21 Mar 2002 20:59:38 -0800
1. Yes, correlation, when done well, can absolutely improve the accuracy and
quality of
your data.
2. SecurityFocus has built one of these for the products that are supported
by ARIS.
MountainWave is another company that has a very comprehensive mapping
knowledgebase.
Intellitactics & ArcSight both use a mapping database (each has a separate
one) to better
map alerts from different IDS to the same catagories of attacks where
appropriate. The
answer is- if you want to buy it, you might be able to do so. If you want to
build it, you just
need the time and resources to do so.
3. I'm not sure I understand the question. Use every method you can-
statistics, boolean logic
statements, pattern matches, combinations of all of the above.
All opinions are my own and in no way reflect the views of my employer.
Toby
> -----Original Message-----
> From: huili@sei.xjtu.edu.cn [mailto:huili@sei.xjtu.edu.cn]
> Sent: Tuesday, March 21, 2000 6:50 PM
> To: focus-ids@securityfocus.com
> Subject: IDS Correlation
>
>
> hi,all
> Recently I am focus on IDS correlation,but I am always
> thinking about the questions:
> 1.Can correlation definitely improve the performance such
> as precison?
> 2.Maybe a comprehensive knowledge base about all kinds of
> IDS's alerts is essential to correlation,but how can we acquire it?
> 3.Supposed that we have the knowledge base,which kinds of
> method should we take to do correlation?
> welcome all kinds of comments about correlation.
>
>
- Previous message: Àî»Ô: "IDS Correlation"
- Maybe in reply to: Àî»Ô: "IDS Correlation"
- Next in thread: Matthew F. Caldwell: "RE: IDS Correlation"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|