Re: Human-oriented IDS, new Paper+Tool
- From: Steffen Wendzel <cdp_doomed@xxxxxxx>
- Date: Sat, 10 Dec 2005 17:51:36 +0100
It uses only human-oriented data. And some of this data-sources
are new: seat-using behavior, room-using behavior, favorite buildings.
and some are already implemented in other IDS or in my old IDS like
the program-using behavior or the time-dependend calculation of the
attacker level.
On Tue, 6 Dec 2005 13:32:34 +0530
Nakul Aggarwal <nakula@xxxxxxxxx> wrote:
> How is it different from other (system level) behavior anomaly
> detection systems ?
>
> On 12/4/05, Steffen Wendzel <cdp_xe@xxxxxxx> wrote:
> > Hi,
> >
> > i wrote a new paper about a kind of IDS i call 'Human oriented
> > IDS' which uses detected differences in users behavior to detect
> > accounts overtaken by attackers.
> >
> > You can find the paper and the beta-version of the tool i call
> > fupids2 at http://cdp.doomed-reality.org/fupids2/
> >
> > Steffen
> >
> > --
> > cdp.doomed-reality.org
> >
> > ------------------------------------------------------------------------
> > Test Your IDS
> >
> > Is your IDS deployed correctly?
> > Find out quickly and easily by testing it
> > with real-world attacks from CORE IMPACT.
> > Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
> > to learn more.
> > ------------------------------------------------------------------------
> >
> >
>
>
> --
> regards
> Nakul Aggarwal
>
> ------------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing it
> with real-world attacks from CORE IMPACT.
> Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
> to learn more.
> ------------------------------------------------------------------------
>
------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------
- References:
- Human-oriented IDS, new Paper+Tool
- From: Steffen Wendzel
- Re: Human-oriented IDS, new Paper+Tool
- From: Nakul Aggarwal
- Human-oriented IDS, new Paper+Tool
- Prev by Date: tired of "what is the best IDS/IPS system?" questions
- Next by Date: Re: Replacing antivirus soft with a real IDS/IPS
- Previous by thread: Re: Human-oriented IDS, new Paper+Tool
- Next by thread: on TASL correlation rules
- Index(es):
Relevant Pages
|