Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

Re: Vulnerability & Exploit Signatures

Subject: Re: Vulnerability & Exploit Signatures
Date: Thu, 16 Jun 2005 10:39:50 -0400
Jackson Yu said:
Do all these vendors license the same set of "base" filters from, say,
Sourcefire / Snort derived rule source in the back?  Is there a
commonality there?  At the end of the day, can I say that "Gee, most
vendors' base set of 1500 IPS signatures are the same, its just the 300 or
so that the vendors have additionally developed on top of that 1500 that
are different!"

That's an interesting question that, as a vendor, I'm very interested in
seeing the answers to. I write N-Code for NFR, and while we use all
available public sources of information we can to get about how to detect
vulnerabilities, all of our code to actually perform detection has been
completely written from scratch in-house. When purchased, the N-Code that
does the detection is viewable in source code so that when we trigger
alerts, it is possible to determine precisely what caused the alert to
trigger. For those who learn to at least read N-Code anyway. :-)


-- 

Dodge

Attachment: pgph33HeQYC36.pgp
Description: PGP signature

<Prev in Thread] Current Thread [Next in Thread>