Anamoly based network IDS

From: vishal p (vishalsec@yahoo.com)
Date: 03/27/03

  • Next message: Lance Spitzner: "Re: Anamoly based network IDS"
    Date: Wed, 26 Mar 2003 23:03:29 -0800 (PST)
    From: vishal p <vishalsec@yahoo.com>
    To: focus-ids@securityfocus.com
    
    

    Hi Lau Ker Chea
    To Understand anomaly base -ids , refer to the
    following link
    http://www.securityfocus.com/infocus/1663
    his is the basic article which shows the difference
    between signature
    base IDS and protocol based IDS
    Anomaly IDS works on the protocol analysis only...
    Symantec MAnhunt is the good example for that..
    Please mail me regarding any query

    Vishal

     Lau Ker Chea <kerchea79@yahoo.com> wrote:may i know
    what type of
    references can i refer to for
    the anomaly-based NIDS?

    is there any resources related to source code using in
    anomaly-based NIDS?

    pls giv me the URL related or the attach files.
    thanks!

    =====
    Regards

    Vishal Pranjale, CISSP

    __________________________________________________
    Do you Yahoo!?
    Yahoo! Platinum - Watch CBS' NCAA March Madness, live on your desktop!
    http://platinum.yahoo.com

    -----------------------------------------------------------
    ALERT: Exploiting Web Applications- A Step-by-Step Attack Analysis
    Learn why 70% of today's successful hacks involve Web Application
    attacks such as: SQL Injection, XSS, Cookie Manipulation and Parameter
    Manipulation.
    http://www.spidynamics.com/mktg/webappsecurity71


  • Next message: Lance Spitzner: "Re: Anamoly based network IDS"

    Relevant Pages

    • RE: Value of "richer" signatures?
      ... Is it that much faster to do "protocol parsing" than ... > Here's an example of how the newer IDS signatures help ... > Let's say you are using a simple packet grepping IDS ...
      (Focus-IDS)
    • RE: ids inquisition
      ... Well, I also fully believe that BOTH protocol analysis, AND pattern ... Dozens of IDS companies out there are merketing millions of dollars ... One signature for ANY buffer overflow, ... > we just knew that this would likely be a vulnerability. ...
      (Focus-IDS)
    • RE: Comparing the performance of two IDS products with different architectures
      ... Comparing the performance of two IDS products with different architectures ... So if you are using protocol analysis, ... You're back to pattern matching. ...
      (Focus-IDS)
    • Re: ids inquisition
      ... Subject: ids inquisition ... Whenever I buy an IDS I life it ... Well, I also fully believe that BOTH protocol analysis, AND pattern ... > we just knew that this would likely be a vulnerability. ...
      (Focus-IDS)
    • RE: Comparing the performance of two IDS products with different architectures
      ... Comparing the performance of two IDS products with different architectures ... An interesting point, “a packet is only tested for a signature when needed, and not when it isn't ... and only tests signatures that apply to those contents. ... could argue all day long about the strengths and weaknesses of “pattern matching” vs “protocol ...
      (Focus-IDS)