Intrusion Detection Systems mailing list archives
a novice question.
From: raj2569 () yahoo com (RajKumar S.)
Date: Sat, 25 Mar 2000 10:33:00 +0530 (IST)
Archive: http://msgs.securepoint.com/ids FAQ: http://www.ticm.com/kb/faq/idsfaq.html IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au hello all, from all the mails i have been getting here i belive that all the IDS products have all the available attack signatures. ie even if the network that i use do not contain any solaris or NT my IDS s/w will check for all the possible exploits that can be mounted against an nt or solaris. now why is this necessary. since the performance of an IDS system can be improved if the number of attack signature can be reduced. one use of having all the attack sig is that it will be possible to log all the possible attacks that are mounted against my network. but most of the time they do not cause any harm, for eg if i am runnig a server v1.8 and it explicitly fixed a bug found in v1.7, am i required to have the attack sig of the bug which was fixed. what use will that sig be to me pl correct me if i got some ideas wrong raj
Current thread:
- Re: Good source of intrusion detection and response steps? Robert Graham (Mar 24)
- Re: Good source of intrusion detection and response steps? -reply mht () clark net (Mar 24)
- Re: Good source of intrusion detection and response steps? Matt Baney (Mar 24)
- Re: Good source of intrusion detection and response steps? Jackie Chan (Mar 24)
- Re: Good source of intrusion detection and response steps? Philippe Bourgeois (Mar 27)
- IDS for Win2k Martins, Fernando (Lisbon) (Mar 27)
- Re: IDS for Win2k Greg Shipley (Mar 27)
- Re: Good source of intrusion detection and response steps? Jackie Chan (Mar 24)
- a novice question. RajKumar S. (Mar 24)
- Re: a novice question. Jackie Chan (Mar 25)
- Re: a novice question. Stuart Staniford-Chen (Mar 25)
- Re: a novice question. Jackie Chan (Mar 25)
- Intruder Alert Chad Harrington (Mar 25)
- CERT advisories,.. Koriun Margaryan (Mar 28)
- RE: CERT advisories,.. Peter Kelly (Mar 28)
- Re: CERT advisories,.. Cliff Rayman (Mar 28)
- RE: CERT advisories,.. Peter A. Thermos (Mar 28)
- RE: A novice question Talisker (Mar 26)
- Re: a novice question. Stuart Staniford-Chen (Mar 25)
