Re: It will work? an idea

Alex Vargas <[email protected]> Wed, 27 Apr 2011 05:27:37 -0500
Newsgroups gmane.comp.security.virus
Message-ID <[email protected]>
Wow so negative. I agree this idea is far fetch, but I thinker should look p=
ast his specific idea instead look at what he wants to accomplish. =46rom a t=
echnical point we should focus on behavior heuristics not signature base. I'=
ve yet to see that in any IDS. What is currently out is signature base ( sno=
rt) or metric based  (bro). We need to inspect future down to a application l=
evel and look at the behavior maybe some AI built into catching new attacks.=


Sent from my iPhone

On Apr 26, 2011, at 12:11 PM, Omar Salvador Alcal=C3=A1 Ruiz <oalcala@scitum=
.com.mx> wrote:

> The problem I see with this is: How do you know which vulns will you cover=
? Most, if not all vulns, are discovered by trial & error, by mistake, or by=
 somebody who is willingly trying to find a weakness in order to get somethi=
ng. Your approach has infinite variations... How will u deal with that?
>=20
> Even if you get a 100% clean and vuln-free code, a thing I think has never=
 happened before, you can try to deceive stuff, or even better, people.
>=20
> Bottom line: I think a vuln-based exploit HIDS/HIPS is comparable to wishi=
ng all people in the world understand technology and how it works: utopia.
>=20
> Regards
>=20
>=20
>=20
> -----Mensaje original-----
> De: [email protected] [mailto:[email protected]] En n=
ombre de [email protected]
> Enviado el: domingo, 24 de abril de 2011 03:37 a.m.
> Para: [email protected]
> Asunto: It will work? an idea
>=20
> Hi Everyone!
>=20
> I have an idea to share with you guys to know whether it can be implemente=
d or not?
>=20
> Idea is, people write exploits for discovered public vulnerabilities, and i=
nfect target system which is not yet patched. If vendor release patch and cl=
ient install released vendor patch or third party, then exploit is outdated f=
or that particular system. And we can write more than one exploit for single=
 vulnerability. Everybody use MS Office, Adobe Acrobat, and we have a finite=
 number of vulnerabilities in these two software, and a number of exploits c=
an be written based on these public vulnerabilities. So, idea is to develop a=
n open source HIDS that defeat vulnerabilities based exploits. Initial focus=
 is on MS Office, Adobe Acrobat because these are commonly used software and=
 if we are able to defeat client side attacks targeting these two software, i=
t would be a remarkable achievement and this HIDS would benefit community by=
 protecting client side attacks in these commonly used software. So:
>=20
> 1-    It will benefit community?
>=20
> 2-    To what level idea is practical?
>=20
> Regards:
>=20
> Umar
>=20
> --------------------------------------------------------------------------=
-
> This list is sponsored by: Black Hat
>=20
> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20=

> technical event for ICT security experts. Featuring 30 hands-on training=20=

> courses and 90 Briefings presentations with lots of new content and new=20=

> tools.  Network with 4,000 delegates from 70 nations.  Visit product=20
> displays by 30 top sponsors in a relaxed setting. =20
>=20
> http://www.blackhat.com
> --------------------------------------------------------------------------=
-
>=20
>=20
> --------------------------------------------------------------------------=
-
> This list is sponsored by: Black Hat
>=20
> Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20=

> technical event for ICT security experts. Featuring 30 hands-on training=20=

> courses and 90 Briefings presentations with lots of new content and new=20=

> tools.  Network with 4,000 delegates from 70 nations.  Visit product=20
> displays by 30 top sponsors in a relaxed setting. =20
>=20
> http://www.blackhat.com
> --------------------------------------------------------------------------=
-
>=20

---------------------------------------------------------------------------
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier 
technical event for ICT security experts. Featuring 30 hands-on training 
courses and 90 Briefings presentations with lots of new content and new 
tools.  Network with 4,000 delegates from 70 nations.  Visit product 
displays by 30 top sponsors in a relaxed setting.  

http://www.blackhat.com
---------------------------------------------------------------------------