Re: deploying honeypots...

Damiano Bolzoni <[email protected]> Tue, 23 Aug 2005 16:31:18 +0200
Newsgroups gmane.comp.security.honeypots
Organization University of Twente
Message-ID <[email protected]>
[email protected] wrote:

> The part I was wondering about was what he was planning to use as a learning
> function - neural networks only make sense if you have feedback telling it if
> the previous decision was correct or not.

What about unsupervised learning?

> And *how* do you recognize a buffer overflow when the protocol spec says some
> given ascii string can be 1024 bytes long, the programmer only provides 256
> bytes of buffer, and the attacker has crafted an all-ascii exploit string?

I don't want to start a flame but...how much do you know about neural
network used for intrusion detection purposes?

-- 
Damiano Bolzoni

[email protected]
PGP public key http://dies.ewi.utwente.nl/~bolzonid/public_key.asc

Distributed and Embedded System Group - University of Twente
P.O. Box 217 7500AE Enschede, The Netherlands
Phone: ++31 53 4894192
Room 3067, Building: ZILVERLING