IDS Terminology

From: Talisker (offthecuff@lineone.net)
Date: 01/24/03

  • Next message: Martin Roesch: "Re: Active response... some thoughts."
    From: "Talisker" <offthecuff@lineone.net>
    To: <focus-ids@securityfocus.com>
    Date: Fri, 24 Jan 2003 18:29:41 -0000
    
    

    Some time ago I wrote an article for SecurityFocus on "Intrusion
    Detection System Terminology", containing brief descriptions of a variety of
    IDS terms. The rapid evolution of IDS has resulted in the article soon
    becoming dated and inaccurate. I wish to update the article introducing new
    and omitted terms as well as correcting a few inaccurate terms. Some
    suggestions are the correction of "resets not being sent from a stealth
    interface" and inclusion of some of the newer evolving terms such as
    Intrusion Prevention Systems etc.

    The problem I encountered with the previous article was finding and
    prioritising all the terms, despite some years of experience and several IDS
    books with indexes I'm still only human, though those of you that know me
    may
    question that.

    I'd really appreciate suggestions from members of suitable terms for
    inclusion, with or without descriptions [off-list]. The article may be of
    use to those entering the field of IDS or others like me who find it hard to
    remember during those senior moments, it is also my intention to revisit the
    article more regularly making it more of a living document.

    Original Articles
    http://www.securityfocus.com/infocus/1213
    http://www.securityfocus.com/infocus/1214

    Thanks for taking the time to read this mail, kindly email me with any
    suggestions.

    -andy

    Taliskers Network Security Tools
    http://www.networkintrusion.co.uk

    Taliskers Network Security Tools
    http://www.networkintrusion.co.uk



    Relevant Pages

    • RE: False Positives
      ... > when no actual exploited attack has ... > when attackers attempt to overload an IDS' alert processing ... > Subject: False Positives ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)
    • RE: IDS failures and avoiding them (WAS: Rather funny; looks like page defacement to me)
      ... Intrusion Analyst aboard an Aircraft Carrier, where my full time job was ... doing Intrusion Detection, I would tend to agree with the assessment ... of false positives that are being generated by your "MUST HAVE" IDS ... your network load is maxing out your 100 Mbps cards on the periphery, ...
      (Focus-IDS)
    • RE: Rather funny; looks like page defacement to me
      ... another security tool (VA, AV, firewall, etc.) that could have done the job ... I am not saying the IDS are always useless, but they are most useful as ... they denigrate Intrusion Prevention Systems and hail ...
      (Focus-IDS)
    • Re: "false positive" inanity
      ... So Mr. Snyder is asking for an IDS that does not need to be configured? ... maximum control of his/her network. ... attack. ... > assuming that it is not an intrusion. ...
      (Focus-IDS)
    • RE: False Positives
      ... There isn't an IDS system that will not report "false positives" ... tools are not actually attacking but testing, and they report an attack, ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)

  • Quantcast