Re: False Positives with IntruVert

From: Michael Rash (mbr@cipherdyne.com)
Date: 04/15/03

  • Next message: Jason V. Miller: "CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability]"
    Date: Tue, 15 Apr 2003 00:02:14 -0400
    From: Michael Rash <mbr@cipherdyne.com>
    To: "Cure, Samuel J" <scure@kpmg.com>
    
    

    On Mar 28, 2003, Cure, Samuel J wrote:

    > While it seems that many IDS/IPS reviewers rank and measure finding attacks
    > high, it would seem equally if not, more important to rank false positives
    > high especially in Prevention mode. Is there any reviewers that have
    > compared the false positives and false alarms of all the IDS/IPS products?
    > Has anyone here compared false positives of Introvert, Snort, Cisco,
    > RealSecure, etc?

    You might be interested in the paper "The Base-Rate Fallacy and its
    Implications for the Difficulty of Intrusion Detection" by Stefan
    Axelsson:

    http://citeseer.nj.nec.com/cache/papers/cs/13832/http:zSzzSzwww.ce.chalmers.sezSzstaffzSzsaxzSzdifficulty.pdf/axelsson99baserate.pdf

    It is heavy on the math side of things, but this is good since it
    begins to put questions about false positives on a rigorous footing.
    (The paper does not answer your specific question above, but it does
    provide an interesting perspective on false positives in general).

    --Mike

    Michael Rash
    http://www.cipherdyne.com
    Key fingerprint = 53EA 13EA 472E 3771 894F AC69 95D8 5D6B A742 839F

    ------------------------------------------------------------------------------
    INTRUSION PREVENTION: READY FOR PRIME TIME?
     
    IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities -
    including intrusion identification, relevancy, direction, impact and analysis - enabling a path to prevention.
     
    Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: http://www.securityfocus.com/IntruVert-focus-ids


  • Next message: Jason V. Miller: "CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability]"

    Relevant Pages

    • RE: True definition of Intrusion Prevention
      ... It detected lots of attacks that were more or less false positives due ... True definition of Intrusion Prevention ... detection with real-time blocking. ...
      (Focus-IDS)
    • RE: False Positives
      ... > when no actual exploited attack has ... > when attackers attempt to overload an IDS' alert processing ... > Subject: False Positives ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)
    • RE: True definition of Intrusion Prevention
      ... my direct human intervention isn't really an "intrusion prevention" measure. ... in general and IT security in specific did it as well. ... Network Intrusion ...
      (Focus-IDS)
    • RE: True definition of Intrusion Prevention
      ... True definition of Intrusion Prevention ... attack in the first place. ... but "Intrusion Blocking" doesn't ring the ears like the ...
      (Focus-IDS)
    • RE: False Positives
      ... There isn't an IDS system that will not report "false positives" ... tools are not actually attacking but testing, and they report an attack, ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)

    Loading