Re: Announcement: Alert Verification for Snort

From: Michael Stone (mstone_at_mathom.us)
Date: 10/24/03

  • Next message: Martin Roesch: "Re: Announcement: Alert Verification for Snort"
    Date: Thu, 23 Oct 2003 21:20:33 -0400
    To: Focus IDS <focus-ids@securityfocus.com>
    
    

    On Thu, Oct 23, 2003 at 12:03:13PM +0200, Konrad Rieck wrote:
    >If Snort or any IDS reports an alert with CVE number, and the
    >corresponding probe (in your case a NASL script) doesn't detect a
    >vulnerability, can you ensure that there isn't one?

    If snort doesn't detect anything can you be sure there isn't an
    intrusion? Why not just record everything? The volume of attacks a large
    site sees requires some kind of filtering; it might be nice to say that
    it's better to report 1000 false positives than to allow 1 attack to go
    undetected, but at some point there is no realistic chance of all the
    data being examined.

    Mike Stone

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_focus-ids_031023
    and use priority code SF4.
    ---------------------------------------------------------------------------


  • Next message: Martin Roesch: "Re: Announcement: Alert Verification for Snort"

    Relevant Pages

    • RE: Snort IDS + TAPS
      ... Subject: Snort IDS + TAPS ... RX and TX streams from your INTERFACE 1 and INTERFACE 2 and run snort on the ... most highly-anticipated industry event of the year. ... Network with over 10,000 of the brightest minds in information security at ...
      (Focus-IDS)
    • Re: Snort IDS + TAPS
      ... the RX and TX streams from your INTERFACE 1 and INTERFACE 2 and run ... Note that when a program such as snort or tcpdump sets the bonded ... > Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Focus-IDS)
    • Re: Snort 2.0.3 released !!!!
      ... it looks like folks should be looking at Snort 2.0.4 (core dump issue ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Focus-IDS)
    • Re: Can anyone recommend a good book?
      ... The book is about the Snort IDS, ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Focus-IDS)
    • Re: SOHO Hardware IDS
      ... >functionality of the Snort IDS. ... Tenable Network Security ... [NeWT Scanner - The easy-to-use vulnerability scanner for XP] ... most highly-anticipated industry event of the year. ...
      (Focus-IDS)