Re: Attack scenarios
"G Ramon Gomez" <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <622FD37285F1584386F5F83D9D233C9C7853A2@SMF-ENTXM-001.sac.ragingwire.net> |
Hi Reinhard, Most conventional correlation theory deals with cross-device correlation. However, you might consider adding baseline-delta analysis to your tool, which is sometimes difficult to do in a signature-based system, and can be far more effective for finding emerging threats. Let me know if you need more information or hints on how it might work. - Ramon ----- Original Message ----- From: [email protected] <[email protected]> To: [email protected] <[email protected]> Sent: Tue May 13 05:51:33 2008 Subject: [prelude-user] Attack scenarios Hello For my master thesis, I've to develop a program like "prelude correlator" but I've to replace the rule-based solution with a neural net. My problem is, that I have to less scenarios where this program would be useful. I've taken a look on sec and prelude-correlator and found the following scenarios: eventscan eventsweep eventstorm brute force worms If you know another scenarios, please add it to the list! Does anyone know scenarios, where a new alert can only be found, when looking on the hids and nids alerts simultaneously? Thanks in advance, Reinhard _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user