<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>IDS Focus</title>
    <link>http://seclists.org/#focus-ids</link>
    <atom:link href="http://seclists.org/rss/focus-ids.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>Technical discussion about Intrusion Detection Systems.  You can also read the archives of a &lt;A HREF=&quot;http://seclists.org/ids/&quot;&gt;previous IDS list&lt;/A&gt;</description>
    <pubDate>Thu, 12 Nov 2009 16:15:14 GMT</pubDate>
    <lastBuildDate>Thu, 12 Nov 2009 16:15:14 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>CfP EWNI2010: 1st European Workshop on Internet Early Warning and Network Intelligence</title>
    <link>http://seclists.org/focus-ids/2009/Nov/1</link>
    <description>&lt;p&gt;Posted by Till Dörges on Nov 12&lt;/p&gt;Hi all,&lt;br&gt;
&lt;br&gt;
attached the CfP for the 1st European Workshop on Internet Early Warning and Network&lt;br&gt;
Intelligence. If you have any questions please don't hesitate to contact me.&lt;br&gt;
&lt;br&gt;
Regards -- Till&lt;br&gt;</description>
    <pubDate>Thu, 12 Nov 2009 16:03:40 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/focus-ids/2009/Nov/1</guid>
  </item>


  <item>
    <title>Re: Re: PCI DSS 11.1 - &quot;.. deploying a wireless IDS/IPS..&quot;. Kismet+Snort?</title>
    <link>http://seclists.org/focus-ids/2009/Nov/0</link>
    <description>&lt;p&gt;Posted by Ray on Nov 02&lt;/p&gt;Although this also does not meet the PCI requirement, one thing you can do &lt;br&gt;
to rapidly detect transient wireless access points is this:&lt;br&gt;
&lt;br&gt;
1. Make sure your network default route leads to your firewall.&lt;br&gt;
2. Monitor the firewall for internal devices trying to do NTP (time sync) &lt;br&gt;
lookups.&lt;br&gt;
&lt;br&gt;
This presumes you have an internal time server system and you have properly &lt;br&gt;
configured your internal systems to not go to the Internet for time.&lt;br&gt;
&lt;br&gt;
It works because...&lt;br&gt;</description>
    <pubDate>Mon, 02 Nov 2009 15:24:06 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/focus-ids/2009/Nov/0</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: Re: PCI DSS 11.1 - &quot;.. deploying a wireless IDS/IPS..&quot;. Kismet+Snort?</title>
    <link>http://seclists.org/focus-ids/2009/Oct/1</link>
    <description>&lt;p&gt;Posted by brian_klumpp on Oct 30&lt;/p&gt;I realize this thread is a little old, but I did want to make a comment in regards to this.  As a QSA, *wired* side &lt;br&gt;
scanning alone would be insufficient to meet the intent of the PCI DSS 11.1 requirement.  There is this quote from PCI &lt;br&gt;
Council:&lt;br&gt;
&lt;br&gt;
&amp;quot;Relying on wired side scanning tools (e.g. tools that scan suspicious hardware MAC addresses on switches) may identify &lt;br&gt;
some unauthorized wireless devices; however, they tend to have high false...&lt;br&gt;</description>
    <pubDate>Fri, 30 Oct 2009 17:59:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/focus-ids/2009/Oct/1</guid>
  </item>


  <item>
    <title>Announcing pcapr Trends</title>
    <link>http://seclists.org/focus-ids/2009/Oct/0</link>
    <description>&lt;p&gt;Posted by kowsik on Oct 01&lt;/p&gt;With the recent influx of pcaps, the number of protocols and pcaps are&lt;br&gt;
getting to the point where interesting trend analysis makes sense. So&lt;br&gt;
we set out to find the meaning of it all with multi-dimensional data&lt;br&gt;
visualization using Motion Charts.&lt;br&gt;
&lt;br&gt;
We wanted to find out&lt;br&gt;
- How does the coverage and #pcaps for a given protocol trend over time?&lt;br&gt;
- When was a protocol first introduced into pcapr?&lt;br&gt;
- What is 42 and what does it have to do with packet...&lt;br&gt;</description>
    <pubDate>Thu, 01 Oct 2009 16:31:54 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/focus-ids/2009/Oct/0</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
