RE: Signature vs Anomaly- again (wasRe: IDS Players?)
From: Carey, Steve T ISD (steve.carey@redstone.army.mil)Date: 06/18/02
- Previous message: Brian Hernacki: "Re: Signature vs Anomaly- again (wasRe: IDS Players?)"
- Maybe in reply to: Vitaly Osipov: "Signature vs Anomaly- again (wasRe: IDS Players?)"
- Next in thread: Greg Shipley: "Re: Signature vs Anomaly- again (wasRe: IDS Players?)"
- Next in thread: Greg Shipley: "Re: IDS Players?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Carey, Steve T ISD" <steve.carey@redstone.army.mil> To: Vitaly Osipov <witt@iol.ie>, Marnix Petrarca <Marnix@DaemonLabs.com>, focus-ids@securityfocus.com Date: Tue, 18 Jun 2002 16:07:11 -0500
Don't know about commercial systems (maybe SilentRunner), but the Shadow IDS
that the U.S. Navy offers does pretty good anomaly detection. Anyone can
download the program for free.
http://www.nswc.navy.mil/ISSEC/CID
Regards,
Steve Carey
-----Original Message-----
From: Vitaly Osipov [mailto:witt@iol.ie]
Sent: Tuesday, June 18, 2002 1:30 PM
To: Marnix Petrarca; focus-ids@securityfocus.com
Subject: Signature vs Anomaly- again (wasRe: IDS Players?)
----- Original Message -----
From: "Marnix Petrarca" <Marnix@DaemonLabs.com>
...
>
> A comment on Signature vs. Protocol vs. Anomaly IDS environments:
>
>
http://www.scmagazine.com/scmagazine/sc-online/2002/article/23/article.html
>
I guess the differences between these two were discussed many times - but
does anybody know of any commercial system (and the one what is used by more
than a couple of people :) ), which is based on anomaly detection rather
than on signature matching? I recently heard that ISS started to use some
neural net features in its sensors (in syn flood or scans detection
perhaps) - is it true?
Regards,
Vitaly.
- Previous message: Brian Hernacki: "Re: Signature vs Anomaly- again (wasRe: IDS Players?)"
- Maybe in reply to: Vitaly Osipov: "Signature vs Anomaly- again (wasRe: IDS Players?)"
- Next in thread: Greg Shipley: "Re: Signature vs Anomaly- again (wasRe: IDS Players?)"
- Next in thread: Greg Shipley: "Re: IDS Players?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|