Intrusion Detection Systems mailing list archives
Re: Anomaly detection [was Re: Assessment tools/Scanners]
From: dugsong () monkey org (Dug Song)
Date: Tue, 12 Oct 1999 09:12:14 -0400 (EDT)
On Mon, 11 Oct 1999, Stuart Staniford-Chen wrote:
I'm not sure that anomaly detection is all that great an idea to install on an end-system for practical real-world intrusion detection. A statistical anomaly detection system (which I assume is what you're talking about)
shouldn't assume. :-) i was referring to anomaly detection as 'grep -v',
as opposed to grep.
re: the rest of what you said, see the previously posted-here:
http://www.monkey.org/~dugsong/talks/ids/
i don't consider 'specification-based ID' to be anything more than anomaly
detection at its very simplest, and i'd appreciate any references you
might have indicating otherwise (i've never seen the work you mention by
Calvin Ko @ UC Davis, for instance)?
-d.
http://www.monkey.org/~dugsong/
Current thread:
- RE: Assessment tools/Scanners Staggs, Michael (Oct 08)
- RE: Assessment tools/Scanners Greg Shipley (Oct 08)
- <Possible follow-ups>
- Re: Re: Assessment tools/Scanners Greg Shipley (Oct 08)
- RE: Assessment tools/Scanners Staggs, Michael (Oct 08)
- Re: Assessment tools/Scanners Vin McLellan (Oct 10)
- Re: Assessment tools/Scanners Dug Song (Oct 10)
- Re: Assessment tools/Scanners Marcus J. Ranum (Oct 10)
- Anomaly detection [was Re: Assessment tools/Scanners] Stuart Staniford-Chen (Oct 11)
- Re: Anomaly detection [was Re: Assessment tools/Scanners] Dug Song (Oct 12)
- Re: Anomaly detection [was Re: Assessment tools/Scanners] Stuart Staniford-Chen (Oct 12)
- Re: Anomaly detection [was Re: Assessment tools/Scanners] Dug Song (Oct 12)
- Re: Assessment tools/Scanners Dug Song (Oct 10)
- Pricing intrusions Stuart Staniford-Chen (Oct 12)
- Re: Pricing intrusions Marcus J. Ranum (Oct 13)
- Re: Pricing intrusions Fernando Trias (Oct 13)
- Fragmentation Question Greg Shipley (Oct 13)
- Re: Fragmentation Question Dug Song (Oct 14)
- Re: Pricing intrusions Ryan M. Ferris (Oct 14)
- Re: Pricing intrusions Stuart Staniford-Chen (Oct 13)
