Re: New Azwalaro project, is a French Open Source Nids project



rmkml wrote:

This project is under developpement (pre alpha version) because not find
on another nids open source product easy to exte
nd,

Well, this is a pity, because working on Snort or Bro or Prelude would
have benefited the community a lot more than starting YARBIDS (Yet
Another Rule Based IDS)...

and work with very good ethereal/wireshark dissector library !

Hint: I may be wrong, but that library is painfully slow for real-time
IDS purposes on real world networks.

Maybe Martin Roesch or another Snort/Sourcefire guy can correct me on
this...

- fix uri content

What do you mean ? If it's the example on your page, I'm sorry to say
that contextual rules for protocols are already in Snort and in almost
any good commercial product...

- work with ssl session

You cannot, unless you disclose private keys to your IDS box. That's Not
Recommended (TM), but there's a lot of ways to do that

- search on mime attachement

Any IDS worth its cost can do that.

- reduce false alert

That's the holy grail, you're welcome to join us in its search :)

Stefano

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Re: Value of "richer" signatures?
    ... Snort, Dragon, and NFR, and I can tell you that they ... Here's an example of how the newer IDS signatures help ... Let's say you are using a simple packet grepping IDS ... > an FTP connection). ...
    (Focus-IDS)
  • Re: ids inquisition
    ... Subject: ids inquisition ... Snort isn't one of them. ... Brian Caswell - CSV output plugin, ... Christian Lademann - active response, ...
    (Focus-IDS)
  • RE: IDS recommendations
    ... Subject: IDS recommendations ... Snort is a relatively raw tool and that usually adds ... >> I can appreciate your comments on the ISS product. ...
    (Focus-IDS)
  • RE: "Free" IDS
    ... I am very surprised noone mentioned Demarc PureSecure IDS solution. ... It cost less than 2000.00 and it runs off of the snort engine and has a big ... if you want to learn snort then just read up on it. ...
    (Focus-IDS)
  • RE: Test tools for IDS
    ... "Sneeze" is great for Snort IDS. ... Captus Networks IPS 4000 ... Intrusion Prevention and Traffic Shaping Technology to: ...
    (Focus-IDS)