Re: Automated IDS Signature Generator?

From: Stefano Zanero (stefano.zanero_at_ieee.org)
Date: 06/18/03

  • Next message: Ali-Reza Anghaie: "Re: Application level IDS?"
    To: <focus-ids@securityfocus.com>
    Date: Wed, 18 Jun 2003 23:42:31 +0200
    
    

    > Is there a utility/function/program that automatically generates an IDS
    > signature based on a recording of a monitored exploit attempt?

    It would be quite useless. For one thing, you must see more than one
    attempt, since polymorphism is obviously an issue: so, you generally want a
    signature which catches most forms of the attack. For another, you
    definitely don't want it to generate false positives.

    In other words you need to recognize a common pattern between different
    exploits, and to avoid including legitimate traffic.

    In other words, you need either a very good AI/datamining approach (still
    working on it, sorry ;) or a very skilled analyst :)

    Stefano

    -------------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
    world's premier technical IT security event! 10 tracks, 15 training sessions,
    1,800 delegates from 30 nations including all of the top experts, from CSO's to
    "underground" security specialists. See for yourself what the buzz is about!
    Early-bird registration ends July 3. This event will sell out. www.blackhat.com
    -------------------------------------------------------------------------------


  • Next message: Ali-Reza Anghaie: "Re: Application level IDS?"

    Relevant Pages

    • RE: IDS, IPS or just rubbish
      ... they do not claim to be a signature based company. ... For the first time in several years, i think that my customers understand why checkpoint claims to be superior. ... Can anyone on this list tell me of a signature-based IDS which picked Slammer up in the 2-odd hours it needed to propogate? ... world's premier technical IT security event! ...
      (Focus-IDS)
    • Re: The Hackers Blocked-Senders List
      ... May I add my part of useless comment to this useless thread? ... in some of your post your own signature is more than 4 lines. ... And suddently you started this dispute whith ChrisFaj. ... from you are disputes, attacks, counter-attacks, ... ...
      (comp.os.linux.misc)
    • Re: Virus Found On USENET!!!!!
      ... > The one-liner I posted, along with my signature, are at this point in ... > the thread useless, so I snip them. ... > Thirty-five or so lines of nonsensical emptiness are useless. ... > signature is useless. ...
      (alt.os.linux)
    • Re: New recording up - comments, please
      ... (link in my signature), but this weekend I posted a new instrumental ... recording. ... You can view my blog at ... How about "Sunday Morning Ramble ... ...
      (rec.music.makers.guitar.acoustic)
    • RE: Strange domain-udp signature
      ... I've done some more digging and this particular signature is ... from a dns global load balancer designed and used by speedera.com. ... world's premier technical IT security event! ...
      (Incidents)

  • Quantcast