Re: Announcement: Alert Verification for Snort

From: Robin Sommer (robin_at_icir.org)
Date: 10/24/03

  • Next message: Sam f. Stover: "Re: Announcement: Alert Verification for Snort"
    Date: Fri, 24 Oct 2003 17:55:48 +0200
    To: focus-ids@securityfocus.com
    
    
    

    On Thu, Oct 23, 2003 at 06:53 -0400, Sam f. Stover wrote:

    > In the not too distant past I would have agreed with this - but I think
    > as IDS implementations grew, the way people describe FPs has changed.
    > I think today's IDS *needs* to know "the additional information about
    > the context and relevance" - because the event you are referring to is
    > what I'll call an "effective FP".

    There is a paper upcoming at ACM's CCS next week in which we use the
    term "contextual signatures" to describe the enhancement of
    Snort-like signatures by incorporating additional context. We
    implemented this for IDS Bro, making use of all its already existing
    mechanisms to provide context (which includes a full scripting
    language).

    > Even better, I want to see the 404 or 403 error, so I
    > can show my boss why I didn't even bother to look into it.

    Actually, this one of our examples: For a certain attack, we want
    the IDS to alert only if the server has not answered with a 4xx.

    The paper is available at http://www.net.in.tum.de/~robin/papers/ccs03.ps

    Robin

    -- 
    Robin Sommer * Room        01.08.055 * www.net.in.tum.de
    TU Munich    * Phone (089) 289-18006 *  sommer@in.tum.de 
    
    



  • Next message: Sam f. Stover: "Re: Announcement: Alert Verification for Snort"

    Relevant Pages

    • Re: Context Menu in List Control
      ... One option is to put those strings in the STRINGTABLE and load them, ... This displays the context menu correctly. ... menu IDs 0 and 1, both of which are extremely bad choices. ... use the tooling to create the menu and its handlers? ...
      (microsoft.public.vc.mfc)
    • Re: Target based IDS review and discussion in Information Security
      ... "target-based IDS" was omitted. ... Lack of host context ... Cisco] both have solutions to solve problem 1 and Sourcefire is working ...
      (Focus-IDS)
    • Re: How to represent links within XML & XSD?
      ... the IDREF doesn't exist in a vacuum; its context may provide additional information. ... Keys, defined in the Schema spec, are a more flexible alternative to IDs and (because there are multiple key spaces rather than a single shared space for all IDs) may be more felxible in this regard. ...
      (comp.text.xml)
    • Re: Bayesian IDS...help
      ... Thank you, I will try out...,but something in the context of IDS ... with real-world attacks from CORE IMPACT. ... Sent from the IDS (Intrusion Detection System) mailing list archive at Nabble.com. ...
      (Focus-IDS)