Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Snort signature packet generator |
|---|---|
| Date: | Thu, 11 Nov 2004 01:29:40 -0300 |
Hi Graeme. We use this tool to test ids like ISS Server Sensor and other products, and works great, its idswakeup, you can obtain it from here : http://www.hsc.fr/ressources/outils/idswakeup/index.html.en Cheers ! -----Original Message----- From: Dirk Geschke [mailto:Dirk_Geschke@genua.de] Sent: Lunes, 08 de Noviembre de 2004 01:38 p.m. To: Graeme Connell Cc: focus-ids@securityfocus.com Subject: Re: Snort signature packet generator Hi Graeme,
I'm attempting to train a neural network using snort, and I'm having trouble getting a good number of "bad" packets, IE: those that snort considers malicious. Since a snort signature is really just a definition of a subset of all possible packets, it seems like it
should
be possible to create a packet that snort considers bad by filling in packet fields based on a snort signature, then filling the rest of the
packet with random garbage. Does anyone know if this type of program has already been created, and if so, where could I find it? Thanks.
fpg, the false-positive generator does exact this. But actually not all keywords are supported. Especially pcre is difficult to implement. fpg is part of the Fast Logging Project for snort: FLoP You can find it at http://www.geschke-online.de/FLoP/ The manual page for fpg is online available: http://www.geschke-online.de/FLoP/fpg.8.html But note: For TCP the most alerts will not work as long as stream4 is used (or equivalent the established flag is set). To get all alerts you should disable stream4 for this case. Best regards Dirk ------------------------------------------------------------------------ -- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------ -- --- Incoming mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.788 / Virus Database: 533 - Release Date: 01/11/2004 --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.788 / Virus Database: 533 - Release Date: 01/11/2004 -------------------------------------------------------------------------- Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. --------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: TippingPoint Releases Open Source Code for FirstIntrusionPrev ention Test Tool, Tomahawk, Brian Smith |
|---|---|
| Next by Date: | Snort vs. compressed HTML, Gary Freeman |
| Previous by Thread: | Re: Snort signature packet generator, Dirk Geschke |
| Next by Thread: | Re: Snort signature packet generator, Martin Roesch |
| Indexes: | [Date] [Thread] [Top] [All Lists] |