RE: need your help,thanks

From: Hayden Searle (hayden.searle_at_safecom.co.nz)
Date: 08/29/04

  • Next message: Raj Malhotra: "session logging IDS"
    Date: Mon, 30 Aug 2004 03:30:47 +1200
    To: "Lily" <xiaoche111@hotmail.com>
    
    

    My experience has been with the ISS products and this has a database
    backend and can produce reports to help you find out what is 'normal'
    for your environment, and it also correlates like attacks, and has the
    ability to check the incoming attacks against known hosts (targets). If
    the "Security Fusion" module is installed, it can tell you if the
    targeted host is vulnerable to the attack.

    False positives take a long time to tune out of your system, and you can
    never fully get rid of them, as new signatures come out all the time.
    IDS's while good to help with your perimeter security are a job in
    themselves, if you want to ensure good effective network security
    principles, and accuracy of the alerts.

    Hayden Searle

    -----Original Message-----
    From: Charles Heselton [mailto:charles.heselton@gmail.com]
    Sent: Wednesday, 25 August 2004 2:42 p.m.
    To: Lily
    Cc: focus-ids@securityfocus.com
    Subject: Re: need your help,thanks

    On Sun, 22 Aug 2004 13:37:22 +0800, Lily <xiaoche111@hotmail.com> wrote:
    > hi,all
    > I am a youngling in IDS.I read some papers in network this days and
    the more I read the little I understand.Because there are so many
    researching area in IDS and I dont know what I'll do.There are some
    questions below:

    Keep reading. ;)

    > 1.If the false alarm rates have being resloved now?I think its a
    essential premise of the area of "response mechanism of IDS" that I want
    to research,do you think so?

    False alarms depend upon the accuracy of your signatures, and the
    peculiarity of your traffic. If the traffic in your environment is
    out of RFC standard, but is considered "normal" for your environment,
    it could produce a lot of false positives, especially with an anomaly
    based IDS. I think that this is something that IDS will always have
    to deal with. You can never have *perfect* detection.

    > 2.Has someone firsthand used a data mining tool just like C5 to
    reduce some data and make a conclusion about anomaly detection?Do you
    think it is advisable?
    > Could you please help me?Thank you in advance.
    >

    I haven't used C5, but my organization has attempted to use an Oracle
    database for such a purpose. There are products out there which are
    supposed to do this sort of correlation for you. I know of Symantec's
    CyberWolf, and I've been told (:-?) that NetIQ does this sort of
    thing, though I have yet to see it. I'm sure there are others as
    well. Anyhow, the key to making a database type situation work is
    being able to rule out possibly anomalous traffic based on historical
    data. Then feed this info back into the IDS. I'm not familiar with
    any IDS that has this capability (yet).

    > Regards
    >
    > Lily

    -- 
    Charlie Heselton
    Network Security Engineer
    #####################################################################################
    Important: This electronic message and attachments (if any) are confidential
    and may be legally privileged. If you are not the intended recipient do not
    copy, disclose or use the contents in any way. Please let us know by return
    e-mail immediately and then destroy this message.
    #####################################################################################
    

  • Next message: Raj Malhotra: "session logging IDS"

    Relevant Pages

    • RE: False Positives
      ... There isn't an IDS system that will not report "false positives" ... tools are not actually attacking but testing, and they report an attack, ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)
    • Re: Snot/state
      ... but not eliminate false positives by enabling this feature. ... > maintaining what the IDS considers state, ... maybe the ultimate IDS is only going to alert me to things that I ... they handle quite a few attacks - attacks that they are well aware of. ...
      (Focus-IDS)
    • RE: Best Method(s) for signature verifcation.
      ... if the IDS is trying to be "smart" it may not listen on ports ... listening in order to get the IDS to see an attack. ... > Subject: Re: Best Methodfor signature verifcation. ... > false positives ...
      (Focus-IDS)
    • RE: Truth about False Positives
      ... Subject: Truth about False Positives ... When using any kind of IDS wether it is host or network based first thing to ... defining false positives & false alarms, and what steps we are taking to ... algorithms into having the most comprehensive set of IDS attack algorithms. ...
      (Focus-IDS)
    • RE: False Positives
      ... > when no actual exploited attack has ... > when attackers attempt to overload an IDS' alert processing ... > Subject: False Positives ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)