Re: IDS detection approaches



Hello Franck,

On 5 Oct 2007 02:29:52 -0000
frankfrydrych@xxxxxxxxx wrote:

Hola,

I would completely go with a signature based IDS. Anomaly based IDS
will not give you the greatest results.

As of signature based IDS...
Let's imagine a so called "0-day", how could you get signature for
a thing that nobody saw ?
I don't say Anomaly based IDS are best, they're complementary
for precisely trying to find what the signature based do not see.


Best regards,

Jean-philippe.


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Re: How to choose an IDS/FW MSS provider
    ... people's IDS technologies, their opaqueness drives a constant nagging ... If a "signature" is written properly then evading it will be ... ISS has had at least ... >> from CORE IMPACT. ...
    (Focus-IDS)
  • Re: Zone Alarm versus Sygate
    ... Not only is BlackIce looking at ... You see an attack will not ... IDS engine to be extremely elementary. ... So Sygate as well as BlackIce use a Signature Analysis IDS engine ...
    (comp.security.firewalls)
  • Re: How to choose an IDS/FW MSS provider
    ... people's IDS technologies, their opaqueness drives a constant nagging ... If a "signature" is written properly then evading it will be ... ISS has had at least ... >> from CORE IMPACT. ...
    (Focus-IDS)
  • Re: How to choose an IDS/FW MSS provider
    ... What is the best way to evade an IDS? ... Open sigs for an IDS/IPS does more harm then good IMO. ... IE a SKILLED attacker wants to attack my network, ... what is out there, a closed signature set, and the ABILITY to add your ...
    (Focus-IDS)
  • RE: Best Method(s) for signature verifcation.
    ... if the IDS is trying to be "smart" it may not listen on ports ... listening in order to get the IDS to see an attack. ... > Subject: Re: Best Methodfor signature verifcation. ... > false positives ...
    (Focus-IDS)

Quantcast