Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Specification-based Anomaly Detection |
|---|---|
| Date: | Thu, 20 Jan 2005 22:05:42 +0100 |
Kohlenberg, Toby wrote:
Right, I got that. But so long as you aren't encrypting the traffic, I can dissect it. I won't always get the fragmentation right but I can probably figure out the application if I look.
That's something that the algorithm we have developed can recognize ;)
Yes, but not by looking at IP/port pairs. You'll need more detail than that.
-- Cordiali saluti, Stefano Zanero Dottorando di Ricerca / Ph.D. Student
Politecnico di Milano - Dip. Elettronica e Informazione Via Ponzio, 34/5 I-20133 Milano - ITALY Tel. +39 02 2399-3660 Fax. +39 02 2399-3411 E-mail: zanero@elet.polimi.it Web: www.elet.polimi.it/upload/zanero
-------------------------------------------------------------------------- Test Your IDS
| Previous by Date: | Re: IDS: Snort detecting distributed syn floods, James Eaton-Lee |
|---|---|
| Next by Date: | Re: Specification-based Anomaly Detection, Adam Powers |
| Previous by Thread: | Re: Specification-based Anomaly Detection, Stefano Zanero |
| Next by Thread: | RE: Specification-based Anomaly Detection, Ofer Shezaf |
| Indexes: | [Date] [Thread] [Top] [All Lists] |