Intrusion Detection Systems mailing list archives
Re: IDS engines put this together
From: mjr () nfr net (Marcus J. Ranum)
Date: Mon, 12 Jun 2000 09:33:52 -0400
Archive: http://msgs.securepoint.com/ids FAQ: http://www.ticm.com/kb/faq/idsfaq.html IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au Lance Spitzner wrote:
Today one of my honeypots was probed for spam relay. Do IDS engines have the 'intelligence' to put this session together and realize the remote system is probing for spam relay sites?
Yeah, NFRs can do very detailed protocol analysis. We have a filter that parses the whole SMTP dialog, including keeping its state (whether it's in DATA or processing directives) and counts RCPTs. I don't think the filter we have checks for source and origin != my network but that's a pretty simple addition. One of the many advantages of having a real programming language in your IDS engine. ;) mjr. ----- Marcus J. Ranum Chief Technology Officer, Network Flight Recorder, Inc. Work: http://www.nfr.net Personal: http://pubweb.nfr.net/~mjr
Current thread:
- IDS engines put this together Lance Spitzner (Jun 11)
- RE: IDS engines put this together Bill Royds (Jun 11)
- connection request to port 25 SHAIFUL HASHIM (Jun 12)
- Re: connection request to port 25 Carric Dooley (Jun 12)
- Does anyone know if there is a firewall in the market that does not filter out ip packets with source route option filled in. Akshay Kumar Sreeramoju (Jun 12)
- Re: connection request to port 25 Joe Dauncey (Jun 18)
- Re: IDS engines put this together Greg Shipley (Jun 12)
- port 25 Tim Slighter (Jun 12)
- Re: IDS engines put this together Martin Roesch (Jun 12)
- <Possible follow-ups>
- Re: IDS engines put this together Marcus J. Ranum (Jun 12)
- Re: IDS engines put this together Marcus J. Ranum (Jun 12)
- Re: IDS engines put this together Martin Roesch (Jun 13)
- Re: IDS engines put this together Mark.Teicher () predictive com (Jun 13)
- Re: IDS engines put this together Andy Bradford (Jun 13)
