Intrusion Detection Systems mailing list archives
Good source of intrusion detection and response steps?
From: baney () shai-seattle com (Matt Baney)
Date: Fri, 24 Mar 2000 08:05:26 -0800
Archive: http://msgs.securepoint.com/ids FAQ: http://www.ticm.com/kb/faq/idsfaq.html IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au What are the best sources for detailed (ie. step by step ) information for detecting and responding to intrusions? I'm looking for something that is more detailed than the CERT advisories, and that may also contain response and forensic details. Something that might includes the necessary steps to detect an intrusion and also provide the necessary response steps to stop or negate the intrusion while preserving forensic information that would be necessary for legal action or be useful in identifying the perpetrator or source of the attack. Does this kind of information exist anywhere? Thanks Matt -- Matt Baney (206)-545-2941 SHAI Seattle, Washington baney () shai-seattle com ------------------------------------------------------- Its hard to predict the unpredictable.
Current thread:
- Source port of Samba Scans? Daniel Swan (Mar 10)
- <Possible follow-ups>
- Re: Source port of Samba Scans? Robert Graham (Mar 10)
- Re: Source port of Samba Scans? Daniel Swan (Mar 10)
- Re: Source port of Samba Scans? Stuart Staniford-Chen (Mar 11)
- comparison of NFR vs RealSecure Thomas Nau (Mar 12)
- Re: comparison of NFR vs RealSecure Talisker (Mar 19)
- Good source of intrusion detection and response steps? Matt Baney (Mar 24)
- Re: Good source of intrusion detection and response steps? Stuart Staniford-Chen (Mar 24)
- Re: Good source of intrusion detection and response steps? Matt Baney (Mar 27)
- question tongchangda (Mar 19)
- Shomit Tap Documentation Jackie Chan (Mar 21)
- Last call for paper - Raid 2000 - Deadline is March 31st Herve Debar (Mar 21)
- Last call for paper - Raid 2000 - Deadline is March 31st Herve Debar (Mar 21)
- Shomit Tap Documentation (fwd) Jackie Chan (Mar 21)
- Mime-Version: 1.0 Lars Olby (Mar 21)
- general questions Lars Olby (Mar 21)
- Freeware ICMP Network Monitor Needed Talisker (Mar 21)
