Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Firewalls (was Re: IDS evaluations procedures) |
|---|---|
| Date: | Tue, 26 Jul 2005 17:08:15 -0400 |
Hi Richard
I am agreed on the difficulty in defining an attack properly. in fact recently i joined a company as a kind as intrusion analyst. Before that i was in academic environment doing my PhD in IDS. what i observed is that signatures are concentrating more on a particular exploit code rather than the true exploit/vulnerability. i am specifically talking about Snort signatures.
I feel that time has come when we should also look at some AI/data mining/ machine learning techniques to get some more insight into the attacks, as now we have high computing devices. During my research, i experimented with many such techniques, but I dont find the acceptability of such techniques in commercial products. I know i may sound more theoretical to all experienced network/system administrators, but i want to bring this issue into the focus. in this way, we can, at least, discuss the feasibility of such techniques and the problems associated with that.
i am looking forward to have some response from all. thanks Sanjay
------------------------------------------------------------------------ Test Your IDS
| Previous by Date: | Re: NetFlow for IDS, Fergus Brooks |
|---|---|
| Next by Date: | RE: IDS alerts / second - Correlation - Virtualization, Swift, David |
| Previous by Thread: | Re: Firewalls (was Re: IDS evaluations procedures), Martin Roesch |
| Next by Thread: | Re: Firewalls (was Re: IDS evaluations procedures), Stefano Zanero |
| Indexes: | [Date] [Thread] [Top] [All Lists] |