Re: It will work? an idea
Alex Vargas <[email protected]> Wed, 27 Apr 2011 05:27:37 -0500
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <[email protected]> |
Wow so negative. I agree this idea is far fetch, but I thinker should look p= ast his specific idea instead look at what he wants to accomplish. =46rom a t= echnical point we should focus on behavior heuristics not signature base. I'= ve yet to see that in any IDS. What is currently out is signature base ( sno= rt) or metric based (bro). We need to inspect future down to a application l= evel and look at the behavior maybe some AI built into catching new attacks.= Sent from my iPhone On Apr 26, 2011, at 12:11 PM, Omar Salvador Alcal=C3=A1 Ruiz <oalcala@scitum= .com.mx> wrote: > The problem I see with this is: How do you know which vulns will you cover= ? Most, if not all vulns, are discovered by trial & error, by mistake, or by= somebody who is willingly trying to find a weakness in order to get somethi= ng. Your approach has infinite variations... How will u deal with that? >=20 > Even if you get a 100% clean and vuln-free code, a thing I think has never= happened before, you can try to deceive stuff, or even better, people. >=20 > Bottom line: I think a vuln-based exploit HIDS/HIPS is comparable to wishi= ng all people in the world understand technology and how it works: utopia. >=20 > Regards >=20 >=20 >=20 > -----Mensaje original----- > De: [email protected] [mailto:[email protected]] En n= ombre de [email protected] > Enviado el: domingo, 24 de abril de 2011 03:37 a.m. > Para: [email protected] > Asunto: It will work? an idea >=20 > Hi Everyone! >=20 > I have an idea to share with you guys to know whether it can be implemente= d or not? >=20 > Idea is, people write exploits for discovered public vulnerabilities, and i= nfect target system which is not yet patched. If vendor release patch and cl= ient install released vendor patch or third party, then exploit is outdated f= or that particular system. And we can write more than one exploit for single= vulnerability. Everybody use MS Office, Adobe Acrobat, and we have a finite= number of vulnerabilities in these two software, and a number of exploits c= an be written based on these public vulnerabilities. So, idea is to develop a= n open source HIDS that defeat vulnerabilities based exploits. Initial focus= is on MS Office, Adobe Acrobat because these are commonly used software and= if we are able to defeat client side attacks targeting these two software, i= t would be a remarkable achievement and this HIDS would benefit community by= protecting client side attacks in these commonly used software. So: >=20 > 1- It will benefit community? >=20 > 2- To what level idea is practical? >=20 > Regards: >=20 > Umar >=20 > --------------------------------------------------------------------------= - > This list is sponsored by: Black Hat >=20 > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20= > technical event for ICT security experts. Featuring 30 hands-on training=20= > courses and 90 Briefings presentations with lots of new content and new=20= > tools. Network with 4,000 delegates from 70 nations. Visit product=20 > displays by 30 top sponsors in a relaxed setting. =20 >=20 > http://www.blackhat.com > --------------------------------------------------------------------------= - >=20 >=20 > --------------------------------------------------------------------------= - > This list is sponsored by: Black Hat >=20 > Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier=20= > technical event for ICT security experts. Featuring 30 hands-on training=20= > courses and 90 Briefings presentations with lots of new content and new=20= > tools. Network with 4,000 delegates from 70 nations. Visit product=20 > displays by 30 top sponsors in a relaxed setting. =20 >=20 > http://www.blackhat.com > --------------------------------------------------------------------------= - >=20 --------------------------------------------------------------------------- This list is sponsored by: Black Hat Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier technical event for ICT security experts. Featuring 30 hands-on training courses and 90 Briefings presentations with lots of new content and new tools. Network with 4,000 delegates from 70 nations. Visit product displays by 30 top sponsors in a relaxed setting. http://www.blackhat.com ---------------------------------------------------------------------------