Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Vulnerability & Exploit Signatures |
|---|---|
| Date: | Thu, 16 Jun 2005 10:39:50 -0400 |
Jackson Yu said:
Do all these vendors license the same set of "base" filters from, say, Sourcefire / Snort derived rule source in the back? Is there a commonality there? At the end of the day, can I say that "Gee, most vendors' base set of 1500 IPS signatures are the same, its just the 300 or so that the vendors have additionally developed on top of that 1500 that are different!"
That's an interesting question that, as a vendor, I'm very interested in seeing the answers to. I write N-Code for NFR, and while we use all available public sources of information we can to get about how to detect vulnerabilities, all of our code to actually perform detection has been completely written from scratch in-house. When purchased, the N-Code that does the detection is viewable in source code so that when we trigger alerts, it is possible to determine precisely what caused the alert to trigger. For those who learn to at least read N-Code anyway. :-) -- Dodge
pgph33HeQYC36.pgp
Description: PGP signature
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | NIPS/NIDS performance evaluation query, snort user |
|---|---|
| Next by Date: | Re: Vulnerability & Exploit Signatures, Matt Jonkman |
| Previous by Thread: | Re: Vulnerability & Exploit Signatures, MadHat |
| Next by Thread: | RE: Vulnerability & Exploit Signatures, Kyle Quest |
| Indexes: | [Date] [Thread] [Top] [All Lists] |