Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

Re: fusion of results from heterogeneous sensors

Subject: Re: fusion of results from heterogeneous sensors
Date: Mon, 05 Jun 2006 09:30:52 -0400
Hello,

Considering the "anomaly based" IDS, i'm not sure a tool likes this exists 
in open source.

Another tool you may check beside of "snort" is "bro" (http://bro-ids.org).
Using the bro's language you can script your own policies and then
with some tweaks,  do and/or check what you want.

Best regards.

On Sat, May 20, 2006 at 09:37:54AM +0530, Raj Malhotra wrote:
Hi All

I am trying to set up a test network comprising of heterogeneous
intrusion detectors. The idea is to use the diverse capabilities of
these detectors to arrive at a decision as to whether an intrusion
took place or not.  I intend to use a signature based ids (snort in
this case), an anomaly based network ids ( i don't know what to use
here), something which is very efficient in detecting scans (port
scans, OS fingerprint attempts) etc.

I would be thankful if folks can suggest freeware which can be used
for the above mentioned purpose

thanks in advance

ral



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>
  • Re: fusion of results from heterogeneous sensors, Jean-Philippe Luiggi <=