Re: Current IDS problems

From: Mark Ryan del Moral Talabis (talabis_at_gmail.com)
Date: 10/19/05

  • Next message: barcajax_at_gmail.com: "Re: Current IDS problems"
    Date: Wed, 19 Oct 2005 08:45:48 +0800
    To: zero <zeroboy@arrakis.es>
    
    

    Hi,

    I myself find false positives a constant problem in IDS. We work with
    honeypots so false positives are a lot less but in actual production
    systems this might tend to be a problem.

    Cheers!
    Ryan Talabis
    Philippine Honeynet Project
    http://www.philippinehoneynet.org

    On 10/19/05, zero <zeroboy@arrakis.es> wrote:
    > Hi all,
    > I would like to know what are the problems people working with IDS sees in
    > them. I mean, what are the things you hate about IDS, think simply you feel
    > are plain wrong or that they should be another way to it.
    >
    > Al comments are greatly appreciated :)
    >
    > Thxs in advance.
    >
    >
    >
    >
    > ------------------------------------------------------------------------
    > Test Your IDS
    >
    > Is your IDS deployed correctly?
    > Find out quickly and easily by testing it
    > with real-world attacks from CORE IMPACT.
    > Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    > to learn more.
    > ------------------------------------------------------------------------
    >
    >

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: barcajax_at_gmail.com: "Re: Current IDS problems"

    Relevant Pages

    • RE: False Positives
      ... There isn't an IDS system that will not report "false positives" ... tools are not actually attacking but testing, and they report an attack, ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)
    • Re: Snot/state
      ... but not eliminate false positives by enabling this feature. ... > maintaining what the IDS considers state, ... maybe the ultimate IDS is only going to alert me to things that I ... they handle quite a few attacks - attacks that they are well aware of. ...
      (Focus-IDS)
    • RE: Best Method(s) for signature verifcation.
      ... if the IDS is trying to be "smart" it may not listen on ports ... listening in order to get the IDS to see an attack. ... > Subject: Re: Best Methodfor signature verifcation. ... > false positives ...
      (Focus-IDS)
    • RE: Truth about False Positives
      ... Subject: Truth about False Positives ... When using any kind of IDS wether it is host or network based first thing to ... defining false positives & false alarms, and what steps we are taking to ... algorithms into having the most comprehensive set of IDS attack algorithms. ...
      (Focus-IDS)
    • RE: False Positives
      ... > when no actual exploited attack has ... > when attackers attempt to overload an IDS' alert processing ... > Subject: False Positives ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)