Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

Re: new intrusion detection system

Subject: Re: new intrusion detection system
Date: Wed, 20 Oct 2004 16:11:49 -0400
Tomas,
The IDS on process monitoring seems interesting. Just wondering any
plan to generate the report based on IDMEF? The reports in the system
are generated using XML (report.xml?).
I am of an opinion that a common output format should be required for
all IDSs. This helps a lot when someone is interested in comparing
them with others.
thanks,
Gautam

On Tue, 19 Oct 2004 14:33:28 +0200 (CEST), Tomas Pluskal
<plusik@pohoda.cz> wrote:

Hello to all,

I have implemented a new type of intrusion detection system for my Master
thesis. I would like to announce this information, in case anyone would be
interested in this research.

The IDS system is designed as a kernel module for FreeBSD 5.2. It is inspired
by the SpamAssassin program, which detects spam by applying a set of tests to
every email message and counting a sum of point score generated by each test.
My IDS system applies a set of tests to every running process in the OS and
counts its score generated by the tests. Therefore, the purpose of the IDS is
not to monitor the network traffic, but rather to monitor the process 
activity.

The current system status is a "working prototype" - it is not ready for
production usage, but it may serve as a good base for an interesting
research.

If you are interested in this topic, please read the details here:
http://plusik.pohoda.cz/thesis/

Thanks,

Tomas

--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE 
IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to 
learn more.
--------------------------------------------------------------------------



--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE 
IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to 
learn more.
--------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>