RE: Automated IDS Signature Generator?

From: Kohlenberg, Toby (toby.kohlenberg_at_intel.com)
Date: 06/19/03

  • Next message: Smokey Lonesome: "Application level IDS?"
    Date: Wed, 18 Jun 2003 15:34:55 -0700
    To: <quakeroats@hushmail.com>, <focus-ids@securityfocus.com>
    
    

    I believe the winner of the Honeynet Project's contest this spring
    created a tool that did that using Honeyd data as as source.

    toby

    > -----Original Message-----
    > From: quakeroats@hushmail.com [mailto:quakeroats@hushmail.com]
    > Sent: Tuesday, June 17, 2003 3:34 PM
    > To: focus-ids@securityfocus.com
    > Subject: Automated IDS Signature Generator?
    >
    >
    >
    >
    > IDS Folk,
    >
    >
    >
    > Is there a utility/function/program that automatically
    > generates an IDS
    >
    > signature based on a recording of a monitored exploit attempt? For
    >
    > example, say the exploit is brought into an isolated lab
    > environment, and
    >
    > we record the whole attack. At the end of the attack, this
    > "thing" spits
    >
    > out automated scripts for any number of IDS solutions. Seems like it
    >
    > would be something that companies like
    > Snort/Symantec/Dragon/etc. might
    >
    > already have, but I've never heard of such a utility.
    >
    >
    >
    > With Love,
    >
    >
    >
    > Quaker Oats
    >
    >
    >
    > "it's mmm mmm good..."
    >
    > --------------------------------------------------------------
    > -----------------
    > Attend the Black Hat Briefings & Training, July 28 - 31 in
    > Las Vegas, the
    > world's premier technical IT security event! 10 tracks, 15
    > training sessions,
    > 1,800 delegates from 30 nations including all of the top
    > experts, from CSO's to
    > "underground" security specialists. See for yourself what
    > the buzz is about!
    > Early-bird registration ends July 3. This event will sell
    > out. www.blackhat.com
    > --------------------------------------------------------------
    > -----------------
    >
    >

    -------------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
    world's premier technical IT security event! 10 tracks, 15 training sessions,
    1,800 delegates from 30 nations including all of the top experts, from CSO's to
    "underground" security specialists. See for yourself what the buzz is about!
    Early-bird registration ends July 3. This event will sell out. www.blackhat.com
    -------------------------------------------------------------------------------


  • Next message: Smokey Lonesome: "Application level IDS?"

    Relevant Pages

    • RE: IDS vs. IPS deployment feedback
      ... IDS vs. IPS deployment feedback ... we all sell what we know. ... of an open source product on the Internet. ...
      (Focus-IDS)
    • Re: IIUG Board election results
      ... be an effective way to seed the market with copies of IDS on Linux and Mac platforms. ... It can be a way to make marketing statements that could not be made directly by IBM because of IBM's internal/infernal marketing rules. ... Why cant/won't IBM get Cisco to be a reference account... ... and don't want to know how to sell into new markets. ...
      (comp.databases.informix)
    • Re: Hello from my DSL
      ... (I hate thinking up new IDs ... and there aren't very many good women characters in games, ... Friend of mine had a trilogy that she gave me to sell. ... :-) I like a couple of pictures too, most notibly Rayne (just wish I ...
      (rec.games.computer.ultima.dragons)
    • Re: IDS as a "legacy" system...
      ... There were no obligations to promote it or convince partners to ... continue to develop ports for IDS. ... And there were no obligations to promote and sell IDS to net new ... care what IBM sells as long as it makes his pillar money. ...
      (comp.databases.informix)
    • Re: Foundry ServerIronXL Question
      ... > Early-bird registration ends July 3. ... This event will sell out. ... world's premier technical IT security event! ... 10 tracks, 15 training sessions, ...
      (Focus-IDS)

  • Quantcast