Re: deploying honeypots...

Damiano Bolzoni <[email protected]> Mon, 22 Aug 2005 15:03:04 +0200
Newsgroups gmane.comp.security.honeypots
Organization University of Twente
Message-ID <[email protected]>
[email protected] wrote:

> neural network will take an action needed from traffic it read and decide if
> those new traffic is dangerous to system, if so then it will disconnect the
> connection (well...it's one of the action will be taken).

Well, I think that you're going to re-connect your system often :)
IMHO, using only neural network to detect intrusion (that's it, you want
to recognize an intrusion attempt) will detect frequently false positive
events. Maybe this situation doesn't matter for you.

Best regards

-- 
Damiano Bolzoni

[email protected]
PGP public key http://dies.ewi.utwente.nl/~bolzonid/public_key.asc

Distributed and Embedded System Group - University of Twente
P.O. Box 217 7500AE Enschede, The Netherlands
Phone: ++31 53 4894192
Room 3067, Building: ZILVERLING