Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: anomaly vs signature |
|---|---|
| Date: | Tue, 01 Aug 2006 09:28:57 +0530 |
Yes...its true that there are more anomaly based ID systems than the misuse based. One possible reason may be the rate of FPs for anomaly based systems. If you look at the research perspective, there is a big gap between the research and commercial ID systems. Reason may be research is focusing on Machine learning, data mining algorithms and such algorithms may be expensive specially in the case of IPS (in case of IDS, it should be OK). However, good thing is that, now I hear companies talking about anomaly based detection engine in their products. Therefore, we are going to see some hybrid IDS too..
there is a list of products on Honeynet..
http://www.honeypots.net/ids/products
thanks -Sanjay
At 04:33 PM 7/26/2006, miaomitiff119 wrote:
Recently I was given a task to survey the relative success of Intrusion Signature Detection and Intrusion Anomaly Detection. Does anyone know how to get a complete list of all IDS products?:) From what I know, there are more signature detection systems on the market than the anomaly detection systems...is that true? What about the hybrid of the two?:)
Thank you!!!!
--
View this message in context: http://www.nabble.com/anomaly-vs-signature-tf2003214.html#a5501191
Sent from the IDS (Intrusion Detection System) forum at Nabble.com.
------------------------------------------------------------------------ Test Your IDS
Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
Sanjay Rawat INTOTO Software (India) Private Limited Homepage: http://sanjay-rawat.tripod.com
------------------------------------------------------------------------ Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
------------------------------------------------------------------------
Sanjay Rawat Senior Software Engineer INTOTO Software (India) Private Limited Uma Plaza, Above HSBC Bank, Nagarjuna Hills PunjaGutta,Hyderabad 500082 | India Office: + 91 40 23358927/28 Extn 422 Website : www.intoto.com Homepage: http://sanjay-rawat.tripod.com
------------------------------------------------------------------------ Test Your IDS
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Next by Date: | Re: IPS - Default blocking policy, jfk |
|---|---|
| Next by Thread: | Re: anomaly vs signature, Roland Dobbins |
| Indexes: | [Date] [Thread] [Top] [All Lists] |