IDS mailing list archives

RE: Anomaly Based Network IDS


From: crayola () optonline net
Date: Tue, 22 Jun 2004 12:43:08 -0400

Is anyone aware of any opensource Network Behaviour Anomoly Detection programs or projects out there? Something that is 
tracking what traffic is going
where, how much, how often, from where, to where, using what ports... etc. Letting
you figure out what is normal.. then alerting when normal gets to far out of wack. 

It would seem to be an excellent partner to a Signature based IDS like Snort or Dragon for gaining real insight into 
what is flowing over the network.

Thanks, 
Mike




---------------------------------------------------------------------------

---------------------------------------------------------------------------


Current thread: