Re: Attack scenarios

"G Ramon Gomez" <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <622FD37285F1584386F5F83D9D233C9C7853A2@SMF-ENTXM-001.sac.ragingwire.net>
Hi Reinhard,
Most conventional correlation theory deals with cross-device correlation.  However, you might consider adding baseline-delta analysis to your tool, which is sometimes difficult to do in a signature-based system, and can be far more effective for finding emerging threats.
Let me know if you need more information or hints on how it might work.

- Ramon


----- Original Message -----
From: [email protected] <[email protected]>
To: [email protected] <[email protected]>
Sent: Tue May 13 05:51:33 2008
Subject: [prelude-user] Attack scenarios

Hello

For my master thesis, I've to develop a program like "prelude 
correlator" but I've to replace the rule-based solution with a neural 
net. My problem is, that I have to less scenarios where this program 
would be useful. I've taken a look on sec and prelude-correlator and 
found the following scenarios:

eventscan
eventsweep
eventstorm
brute force
worms

If you know another scenarios, please add it to the list!

Does anyone know scenarios, where a new alert can only be found, when 
looking on the hids and nids alerts simultaneously?

Thanks in advance,

Reinhard
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.