Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Snort signature packet generator |
|---|---|
| Date: | Mon, 8 Nov 2004 10:30:47 -0500 |
There is a program to do just that: Snot [0]. But this strikes me as a very inaccurate way to train a neural network. You would be using purely crafted packets which may or may not appear as an actual attack would. Snot is made to fill up snort logs, and the packets it creates are done purely to trip rules, not appear 100% valid. Instead I would download exploits and scanners like Nessus and use actual attacks to train your neural net. -Adam. [0] http://www.stolenshoes.net/sniph/index.html -----Original Message----- From: Graeme Connell [mailto:gconnell@middlebury.edu] Sent: Friday, November 05, 2004 12:29 PM To: focus-ids@securityfocus.com Subject: Snort signature packet generator I'm attempting to train a neural network using snort, and I'm having trouble getting a good number of "bad" packets, IE: those that snort considers malicious. Since a snort signature is really just a definition of a subset of all possible packets, it seems like it should be possible to create a packet that snort considers bad by filling in packet fields based on a snort signature, then filling the rest of the packet with random garbage. Does anyone know if this type of program has already been created, and if so, where could I find it? Thanks. --Graeme Connell -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. -------------------------------------------------------------------------- **************************************************************************************** Note: The information contained in this message may be privileged and confidential and thus protected from disclosure. If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify us immediately by replying to the message and deleting it from your computer. Thank you. **************************************************************************************** -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Snort signature packet generator, Jeff Dell |
|---|---|
| Next by Date: | Re: TippingPoint Releases Open Source Code for FirstIntrusionPrev ention Test Tool, Tomahawk, ADT |
| Previous by Thread: | Re: Snort signature packet generator, Stefano Zanero |
| Next by Thread: | Re: Snort signature packet generator, ADT |
| Indexes: | [Date] [Thread] [Top] [All Lists] |