some questions!

From: jason cheng (jason_cheng2003@hotmail.com)
Date: 03/01/03

  • Next message: Jason V. Miller: "Snort RPC Vulnerability"
    Date: 1 Mar 2003 12:10:12 -0000
    From: jason cheng <jason_cheng2003@hotmail.com>
    To: focus-ids@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

      hello,everyone!
      I am a chinese student.I am very interested in NIDS,especially protocol
    analysis an pattern match NIDS.I am going to wirte a thesis about this
    topic.But I do not know it.I have make a research on it for several months.
      I have some questions that I can not understand yet.I hope get your
    answer urgently.
      1)I know pattern match is used in protocol analysis NIDS.Could you tell
    me which module pattern is applied and what role is it in protocol
    analysis NIDS?
      2)Is AC_BM algorithm used in snort now?what is the performance data of
    this algorithm?
      3)Protocol anomaly is one subset of protocol analysis,then what other
    subsets protocol analysis contain?
      4)As we know,packets are decoded to detect if they comply with protocol
    specification.In Mr. Robert Graham's article,he say "protocol are
    decoded".Could you tell me whether they are same one?

       Thank you very much!

    -----------------------------------------------------------
    <Pre>Lose another weekend managing your IDS?
    Take back your personal time.
    15-day free trial of StillSecure Border Guard.</Pre>
    <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A>



    Relevant Pages

    • Re: Encryption Algorithm Footprint
      ... a protocol, you can gather which symetric algorithm was used for transit. ... negating the need for a negotiation phase. ... Subject: Encryption Algorithm Footprint ...
      (Vuln-Dev)
    • Re: [9fans] (no subject)
      ... and see if there exists somehost on protocol $protocol for service 9fs. ... the current algorithm doesn't check to see if any servers were found. ... the first version in sourcesdump also has the break. ...
      (comp.os.plan9)
    • Re: [9fans] (no subject)
      ... and see if there exists somehost on protocol $protocol for service 9fs. ... the current algorithm doesn't check to see if any servers were found. ... the first version in sourcesdump also has the break. ...
      (comp.os.plan9)
    • Re: Algorithms to generate permutations
      ... > Assuming other aspects such as protocol and implementation have been ... algorithm] being broken because the underlying cipher was weak. ... We are talking about future UNKNOWN attacks. ... could shave bits off a dozen ciphers... ...
      (sci.crypt)
    • Re: Algorithms to generate permutations
      ... "Tom St Denis" writes: ... >> itself being the point of failure. ... >algorithm] being broken because the underlying cipher was weak. ... >always proven to be from protocol or user side of things. ...
      (sci.crypt)