Packet/Protocol Anomaly Detection with IDS

From: Harald (brain_at_paranoit.at)
Date: 05/19/05

  • Next message: Net Shark: "RE: Checkpoint SmartDefense"
    Date: 19 May 2005 20:50:55 -0000
    To: focus-ids@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Hi Community,

    im a student, and at the moment im searching
    for some input to write my exam.

    The title is "Packet/Protocol Anomaly Detection with IDS", i already got some good input.
    But some things are quiet hard to find.

    What i need is some examples on attacks,
    on specific protocols, like ftp, http, tcp ...
    I know there are attacks like Dos or Buffer Overflows.
    But i need some more.

    Maybe you can tell me some good ressources or
    examples.

    Thanks all, and sorry for my english.

    mfg
    harry

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Net Shark: "RE: Checkpoint SmartDefense"

    Relevant Pages

    • RE: Intrusion Prevention
      ... Coverage what can it detect; this covers basic attacks, ... IDS purchase. ... While doing these implementations and while working in an IDS vendor I ... sometimes we're told that we cannot see the testing methodology upfront. ...
      (Focus-IDS)
    • RE: Changes in IDS Companies?
      ... This means you need a standard IDS sitting behind it/next to it watching the ... Things like port scans and DoS attacks ... >>> If people are running insecure web servers, ... > Pretty sad state of affairs, when people don't update their patches at ...
      (Focus-IDS)
    • RE: Best Method(s) for signature verification.
      ... on this list - and other IDS lists - for the means to test their IDS ... When I say we use IDS Informer for our signature recognition testing, ... should point out that we do NOT use all the default attacks! ... (IIS attacks run against Apache web servers on Unix - "real ...
      (Focus-IDS)
    • Re: How to choose an IDS/FW MSS provider
      ... First, "recording everything" is not what IDS's were EVER meant for, ... others can create "audit" trails of every web request, every mail, every ... >detect attacks by inspecting layer 3 headers for prohibited IP ... >facility with an IDS or IPS deployed. ...
      (Focus-IDS)
    • Re: Alarming (was protocol analysis)
      ... Obviously, there are different ways to "detect" attacks, but John uses the ... no one should ever "rely" on any IDS for our ... As for Johns Metaphor of the motion sensor vs the pressure sensor, ... toward Intrusion Prevention as opposed to just Intrusion Detection. ...
      (Focus-IDS)