IDS mailing list archives
Re: A Network IPS Proposal (was Definition of Zero Day Protection)
From: Johnny Calhoun <jcalhoun () lurhq com>
Date: Mon, 16 Aug 2004 09:45:23 -0400
On Thursday 12 August 2004 20:35, Shaiful wrote:
similar pattern
How do you define "similar pattern"? Detecting similar patterns/signatures is trivial if the signature is known in advance, but how do you know if something is "similar" before it even happens? And if it is KNOWN then it probably already has a signature right? Anomaly based Intrusion Detection/Prevention is very complex, much more complex than just trapping traffic and predicting similar patterns. -- Johnny Calhoun, GCIA Information Security Analyst LURHQ 843-903-4376 opt2 jcalhoun () lurhq com -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
Current thread:
- Re: Definition of Zero Day Protection, (continued)
- Re: Definition of Zero Day Protection Andy Cuff (Aug 11)
- RE: Definition of Zero Day Protection Drew Copley (Aug 09)
- Re: Definition of Zero Day Protection Devdas Bhagat (Aug 13)
- RE: Definition of Zero Day Protection Fulp, J.D. USA (Aug 09)
- RE: Definition of Zero Day Protection Joshua Berry (Aug 10)
- RE: Definition of Zero Day Protection Brian Smith (Aug 10)
- RE: Definition of Zero Day Protection Teicher, Mark (Mark) (Aug 10)
- RE: Definition of Zero Day Protection Brian Smith (Aug 10)
- RE: Definition of Zero Day Protection Drew Copley (Aug 10)
- A Network IPS Proposal (was Definition of Zero Day Protection) Shaiful (Aug 13)
- Re: A Network IPS Proposal (was Definition of Zero Day Protection) Johnny Calhoun (Aug 16)
- Re: A Network IPS Proposal (was Definition of Zero Day Protection) Stefano Zanero (Aug 17)
- Re: A Network IPS Proposal (was Definition of Zero Day Protection) Shaiful (Aug 17)
- A Network IPS Proposal (was Definition of Zero Day Protection) Shaiful (Aug 13)
- RE: Definition of Zero Day Protection Drew Simonis (Aug 10)
- Re: Definition of Zero Day Protection Stefano Zanero (Aug 11)
- Re: Definition of Zero Day Protection hidsbr (Aug 10)
- RE: Definition of Zero Day Protection Joseph Hamm (Aug 11)
