Re: Specification-based Anomaly Detection

From: Stefano Zanero (zanero_at_elet.polimi.it)
Date: 01/13/05

  • Next message: Ofer Shezaf: "RE: Specification-based Anomaly Detection"
    Date: Thu, 13 Jan 2005 21:14:19 +0100
    To: "Kohlenberg, Toby" <toby.kohlenberg@intel.com>
    
    

    Kohlenberg, Toby wrote:

    >>- and that anomaly detection (in particular techniques which are not
    >>rate-based) is a relative "newcomer" in the COMMERCIAL field of
    >>intrusion detection, where most of the products are built on a misuse
    >>detection approach.
    >
    > Really? What would you call CMDS? Which was a commercial system that
    > used anomaly detection by building user profiles and was available from
    > ODS in the mid-90s?

    My omission here: I meant NETWORK intrusion detection, as we were
    talking about NIDS in those posts. Commercial anomaly detection systems
    exist.

    -- 
    Cordiali saluti,
    Stefano Zanero
    Dottorando di Ricerca / Ph.D. Student
    Politecnico di Milano - Dip. Elettronica e Informazione
    Via Ponzio, 34/5 I-20133 Milano - ITALY
    Tel.    +39 02 2399-3660
    Fax.    +39 02 2399-3411
    E-mail: zanero@elet.polimi.it
    Web:    www.elet.polimi.it/upload/zanero
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: Ofer Shezaf: "RE: Specification-based Anomaly Detection"

    Relevant Pages

    • Re: True definition of Intrusion Prevention
      ... >Prevention versus Network Intrusion Detection, ... to be monitoring the integrity of the host's operation. ...
      (Focus-IDS)
    • re: windows 2000 Intrustion Detection
      ... even to the point of installing ... So, I'd recommend prevent first, then detection. ... Do You Yahoo!? ...
      (Security-Basics)
    • Re: Intrusion Prevention
      ... > approach to IDS technologies and provides a number of advantages over ... > other detection systems, such as proactively detecting reconnaissance ... 100% no false positives, 'proactive' intrusion detection, intrusion ...
      (Focus-IDS)
    • Re: windows restriction is blocking my intrusion detection from turnin
      ... h4xor wrote: ... > able to be turned on and get the same message saying that it has ... ok i tried installing the update for the intrusion detection and once ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: IDS thoughts
      ... who most consider the mother of Anomaly Detection (because of her ... This is pretty obvious to me, too: please excuse me if this wasn't clear in ... anomaly detection is like allowing only what you want. ... INTRUSION PREVENTION: READY FOR PRIME TIME? ...
      (Focus-IDS)