Re: SIM solution - Objectives ?

Stefano Zanero <[email protected]>
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <[email protected]>
Mikael Kuisma wrote:
> Hi Saudi,
> 
> To detect changes in your network configuration based on firewall logs,
> you can use the ASDIC network traffic analysis system. It registers the
> standard traffic and reports changes, based on whatever criteria of you
> choice. Works fine of both Stonegate and Firewall-1 logs. It uses a
> quite neat (and as far I know, unique)  mechanism of aggregating
> relating log entries, keeping the output short and concise.

It looks to me a rather rough attempt to replicate early '90s research
on anomaly detectors...

It may work well or not, but is all but unique :)

-- 
Cordiali saluti,
Stefano Zanero

Politecnico di Milano - Dip. Elettronica e Informazione
Via Ponzio, 34/5 I-20133 Milano - ITALY
Tel.    +39 02 2399-4010
Fax.    +39 02 2399-3411
E-mail: [email protected]
Web:    www.elet.polimi.it/upload/zanero
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.