RE: It will work? an idea

"IT_H_Security" <[email protected]> Thu, 28 Apr 2011 12:02:33 +0530
Newsgroups gmane.comp.security.virus
Message-ID <E7FBBA32A2342248BAABA3BA779A73AB052250A1@SBHCP2MSGV1.SATYAMBPO.COM>
Hello Umar,

Your Idea is quite fantastic but following are the things which pop up
into my mind:

1. Even If we make databases of all the exploits available till date on
earth (practically impossible), how are we going to identify zero day
exploits.=20
2. Let's think of starting with a good amount of categorized exploits
for MS Office. How are going to differentiate between a normal MS Office
query (over network) and an exploited MS Office query.
3. What approach can be followed to remove FALSE positives (above two
points actually mean handling of FALSE positives).

Umar, I am really interested in HIDS concept, Please revert If my
concerns are legitimate.=20

FYI, I am a new bee to IT Security with just 2 yrs of experience, so
please ignore my points if they are wrong.

Thanks in Adv.

Nutan Vishwakarma

-----Original Message-----
From: [email protected] [mailto:[email protected]]
On Behalf Of [email protected]
Sent: Sunday, April 24, 2011 2:07 PM
To: [email protected]
Subject: It will work? an idea

Hi Everyone!

I have an idea to share with you guys to know whether it can be
implemented or not?

Idea is, people write exploits for discovered public vulnerabilities,
and infect target system which is not yet patched. If vendor release
patch and client install released vendor patch or third party, then
exploit is outdated for that particular system. And we can write more
than one exploit for single vulnerability. Everybody use MS Office,
Adobe Acrobat, and we have a finite number of vulnerabilities in these
two software, and a number of exploits can be written based on these
public vulnerabilities. So, idea is to develop an open source HIDS that
defeat vulnerabilities based exploits. Initial focus is on MS Office,
Adobe Acrobat because these are commonly used software and if we are
able to defeat client side attacks targeting these two software, it
would be a remarkable achievement and this HIDS would benefit community
by protecting client side attacks in these commonly used software. So:

1-	It will benefit community?

2-	To what level idea is practical?

Regards:

Umar

------------------------------------------------------------------------
---
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier

technical event for ICT security experts. Featuring 30 hands-on training

courses and 90 Briefings presentations with lots of new content and new=20
tools.  Network with 4,000 delegates from 70 nations.  Visit product=20
displays by 30 top sponsors in a relaxed setting. =20

http://www.blackhat.com
------------------------------------------------------------------------
---

DISCLAIMER:
This email (including any attachments) is intended for the sole use of the =
intended recipient/s and may contain material that is CONFIDENTIAL AND PRIV=
ATE COMPANY INFORMATION. Any review or reliance by others or copying or dis=
tribution or forwarding of any or all of the contents in this message is ST=
RICTLY PROHIBITED. If you are not the intended recipient, please contact th=
e sender by email and delete all copies; your co-operation in this regard i=
s appreciated.



---------------------------------------------------------------------------
This list is sponsored by: Black Hat

Attend Black Hat USA, July 28-August 2 in Las Vegas, the world's premier 
technical event for ICT security experts. Featuring 30 hands-on training 
courses and 90 Briefings presentations with lots of new content and new 
tools.  Network with 4,000 delegates from 70 nations.  Visit product 
displays by 30 top sponsors in a relaxed setting.  

http://www.blackhat.com
---------------------------------------------------------------------------